Sensitive Information Exposure Affecting airbrake Open this link in a new tab package, versions <=0.3.8


0.0
medium
  • Attack Complexity

    High

  • Confidentiality

    High

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • snyk-id

    npm:airbrake:20160215

  • published

    10 Oct 2016

  • disclosed

    15 Feb 2016

  • credit

    Hrvoje Šimić

Introduced: 15 Feb 2016

CWE-200 Open this link in a new tab

Overview

airbrake is a Node.js notifier for the Airbrake bug and error tracking service. Versions prior to 0.4.0 serialized all environment variables and could lead to sensitive information exposure.

Remediation

Upgrade airbrake version 0.4.0 or greater.