AIKIDO-2024-10162

botocore is vulnerable to Insertion of Sensitive Information into Log File

5

Low

botocore

AIKIDO-2024-10162: botocore is vulnerable to Insertion of Sensitive Information into Log File in versions 1.29.150 - 1.34.136.

Insertion of Sensitive Information into Log File
Vuln in 1.29.150 - 1.34.136
Fixed in 1.34.137
No CVE available
TL;DR

Affected versions of this package are vulnerable to Exposure of Sensitive Information into the Log files, when importing or exporting a TR31KeyBlock.

Who does this affect?

You're affected if you are using a vulnerable version of the package.

How can it be fixed?

Upgrade botocore to a patch version.

Are you
to these issues?
Connect your GitHub, GitLab, Bitbucket or Azure DevOps account to start scanning your repos for free.
Start For Free
Your data won't be shared · Read-only access
Logo
© 2024 Aikido Security BV | BE0792914919
🇪🇺 Grauwpoort 1, 9000 Ghent, Belgium
🇺🇸 95 Third St, 2nd Fl, San Francisco, CA 94103, US