Information Exposure Through an Error Message Affecting github.com/huandu/facebook/v2 package, versions <2.7.2
Threat Intelligence
Exploit Maturity
Proof of concept
EPSS
0.05% (17th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-GOLANG-GITHUBCOMHUANDUFACEBOOKV2-7116684
- published 26 May 2024
- disclosed 24 May 2024
- credit seiyab
Introduced: 24 May 2024
CVE-2024-35232 Open this link in a new tabHow to fix?
Upgrade github.com/huandu/facebook/v2
to version 2.7.2 or higher.
Overview
Affected versions of this package are vulnerable to Information Exposure Through an Error Message in the error message handling process. An attacker can expose sensitive information by causing an HTTP request to fail.
Note
Client applications with the following conditions can be affected: Logs error message from this module, or returns error message to client as something like HTTP response, or uses error messages somewhere.
References
CVSS Scores
version 3.1