@salesforce/core is vulnerable to Insertion of Sensitive Information into Log File
18
Low Risk
Affected versions of this package expose sensitive authentication tokens in application logs because the logging filters fail to redact certain JWT patterns. As a result, the application may write valid credentials to log files in cleartext, increasing the risk of unauthorized access if an attacker obtains log data. The issue is fixed by extending the logging redaction logic to detect and properly mask JWT tokens before they are written to logs.
You are affected if you are using a vulnerable version of the package.
@salesforce/core is vulnerable to Insertion of Sensitive Information into Log File in versions 0.0.1 - 8.25.1.
Upgrade @salesforce/core to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant