CVE-2019-14367: Infoleak
Slack-Chat through 1.5.5 leaks a Slack Access Token in source code. An attacker can obtain a lot of information about the victim's Slack (channels, members, etc.).
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2019-14367?
CVE-2019-14367 has a medium severity rating due to the potential exposure of sensitive Slack Access Tokens.
How do I fix CVE-2019-14367?
To fix CVE-2019-14367, update the Slack-Chat plugin to version 1.5.6 or later to mitigate the leak of access tokens.
What is affected by CVE-2019-14367?
CVE-2019-14367 affects all versions of the Slack-Chat plugin up to and including version 1.5.5.
What information can be compromised due to CVE-2019-14367?
An attacker exploiting CVE-2019-14367 can access sensitive information such as Slack channels, members, and messages.
Is CVE-2019-14367 being actively exploited?
While specific exploit attempts may not be reported, the nature of CVE-2019-14367 suggests potential for exploitation if the vulnerability is not addressed.