slack-morphism is vulnerable to Information Disclosure
53
Medium Risk
Slack Morphism's signature verifier stores the correct HMAC for an invalid request in SlackEventWrongSignatureError.generated_hash, and both Debug and Display print that value, so a default listener error handler logs the correct signature when verification fails. A request with a chosen timestamp and body and an invalid signature makes the verifier compute and leak that request's correct signature into the logs, so the same request can be resent within the five minute freshness window and pass verification without the signing secret. The fix drops the expected signature from the error entirely and truncates the received signature to a short prefix before formatting.
You are affected if you are using a version that falls within the vulnerable range and someone outside your trust boundary can both reach your Slack event endpoint and read the resulting signature verification error logs.
slack-morphism is vulnerable to Information Disclosure in versions 1.0.0 - 2.27.0.
Upgrade the slack-morphism library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.