A potential logging of the firestore key via logging within nodejs-firestore exists - Developers who were logging objects through this._settings would be logging the firestore key as well potentially exposing it to anyone with logs read access. We recommend upgrading to version 6.1.0 to avoid this issue
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-3097 | A potential logging of the firestore key via logging within nodejs-firestore exists - Developers who were logging objects through this._settings would be logging the firestore key as well potentially exposing it to anyone with logs read access. We recommend upgrading to version 6.1.0 to avoid this issue |
Github GHSA |
GHSA-4g6q-77j7-vvjc | Logging of the firestore key within nodejs-firestore |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://github.com/googleapis/nodejs-firestore/pull/1742 |
|
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Google
Published:
Updated: 2024-08-02T08:28:21.810Z
Reserved: 2023-12-01T11:10:57.359Z
Link: CVE-2023-6460
No data.
Status : Modified
Published: 2023-12-04T13:15:07.800
Modified: 2024-11-21T08:43:54.233
Link: CVE-2023-6460
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA