ops@2.5.0 vulnerabilities

The Python library behind great charms

Direct Vulnerabilities

Known vulnerabilities in the ops package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Information Exposure Through Log Files

ops is a The Python library behind great charms

Affected versions of this package are vulnerable to Information Exposure Through Log Files through the handling of errors in subprocess.CalledProcessError when executing CLI commands that include sensitive information. An attacker can gain access to sensitive data by exploiting the logging of error details which include secret values.

How to fix Information Exposure Through Log Files?

Upgrade ops to version 2.15.0 or higher.

[2.0.0,2.15.0)