Description
The airbrake module 0.3.8 and earlier defaults to sending environment variables over HTTP. Environment variables can often times contain secret keys and other sensitive values. A malicious user could be on the same network as a regular user and intercept all the secret keys the user is sending. This goes against common best practice, which is to use HTTPS.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-0258 | The airbrake module 0.3.8 and earlier defaults to sending environment variables over HTTP. Environment variables can often times contain secret keys and other sensitive values. A malicious user could be on the same network as a regular user and intercept all the secret keys the user is sending. This goes against common best practice, which is to use HTTPS. |
Github GHSA |
GHSA-856x-cp3q-47vg | Insecure Default Configuration in airbrake |
References
History
No history.
Status: PUBLISHED
Assigner: hackerone
Published:
Updated: 2024-09-16T17:48:45.037Z
Reserved: 2017-10-29T00:00:00.000Z
Link: CVE-2016-10530
No data.
Status : Modified
Published: 2018-05-31T20:29:00.987
Modified: 2024-11-21T02:44:12.643
Link: CVE-2016-10530
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA