rustler_precompiled is vulnerable to Insertion of Sensitive Information into Log File
30
Low Risk
Affected versions of this package are vulnerable to sensitive data exposure in debug logs due to unredacted credentials in URLs, allowing attackers who gain access to these logs to extract usernames and passwords from userinfo components, potentially leading to unauthorized access to systems or accounts; the patch mitigates this by redacting userinfo with '[REDACTED]' before logging.
You are affected if you are using a version that falls within the vulnerable range.
rustler_precompiled is vulnerable to Insertion of Sensitive Information into Log File in versions 0.1.0 - 0.8.3.
Upgrade the rustler_precompiled library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant