github.com/zalando/skipper is vulnerable to Insertion of Sensitive Information into Log File
30
Low Risk
Affected versions of this package are vulnerable to information disclosure due to Inadequate Masking of Sensitive Query Parameters in Access Logs, where the abscense of a proper redaction filter fails to properly obfuscate all sensitive query parameters, potentially leaving credentials or tokens exposed in access logs; an attacker could exploit this by accessing or intercepting these logs to harvest unmasked data, leading to account compromise or further system intrusion.
You are affected if you are using a version that falls within the vulnerable range.
github.com/zalando/skipper is vulnerable to Insertion of Sensitive Information into Log File in versions 0.10.157 - 0.22.186.
Upgrade the github.com/zalando/skipper library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant