WARNING: THIS SITE IS A MIRROR OF GITHUB.COM / IT CANNOT LOGIN OR REGISTER ACCOUNTS / THE CONTENTS ARE PROVIDED AS-IS / THIS SITE ASSUMES NO RESPONSIBILITY FOR ANY DISPLAYED CONTENT OR LINKS / IF YOU FOUND SOMETHING MAY NOT GOOD FOR EVERYONE, CONTACT ADMIN AT ilovescratch@foxmail.com
You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
matrix-sdk 0.6.0 logs access tokens
Moderate severity
GitHub Reviewed
Published
Oct 25, 2022
to the GitHub Advisory Database
•
Updated Jan 7, 2023
When sending Matrix requests using an affected version of matrix-sdk in an application that writes logs using tracing-subscriber (in a way that includes fields of tracing spans such as tracing_subscribers default text output from the fmt module), these logs will contain the user's access token.
When sending Matrix requests using an affected version of
matrix-sdkin an application that writes logs usingtracing-subscriber(in a way that includes fields of tracing spans such astracing_subscribers default text output from thefmtmodule), these logs will contain the user's access token.References