@logtape/redaction is vulnerable to Insertion of Sensitive Information into Log File
35
Low Risk
Affected versions of this package are vulnerable to sensitive information exposure in logs due to incomplete redaction in the redactByField() function. Objects passed via the {*} wildcard retained their original references, causing sensitive fields to appear in log messages even when properties were marked for redaction. The issue is fixed by ensuring redactByField() properly redacts sensitive values both in the wildcard-passed objects and within the message array itself.
You are affected if you are using a version that falls within the vulnerable range.
@logtape/redaction is vulnerable to Insertion of Sensitive Information into Log File in versions 0.0.1 - 1.1.2 and 1.2.0 - 1.2.1.
Upgrade the @logtape/redaction library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant