bamboohr/api is vulnerable to Generation of Error Message Containing Sensitive Information
30
Low Risk
Affected versions of this package are vulnerable to Information Disclosure due to incomplete redaction in its logging feature. This flaw allows sensitive data, such as API keys and passwords, to be exposed in plaintext within logs. An attacker could exploit this by submitting data in a way that bypasses the redaction filters, potentially leading to credential theft for further attacks.
You are affected if you are using a version that falls within the vulnerable range.
bamboohr/api is vulnerable to Generation of Error Message Containing Sensitive Information in versions 1.0.0 - 1.2.0.
Upgrade the bamboohr/api library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant