First published: Fri Sep 06 2019(Updated: )
The Airbrake Ruby notifier 4.2.3 for Airbrake mishandles the blacklist_keys configuration option and consequently may disclose passwords to unauthorized actors. This is fixed in 4.2.4 (also, 4.2.2 and earlier are unaffected).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Airbrake | =4.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-16060 is a vulnerability in the Airbrake Ruby notifier 4.2.3 that mishandles the blacklist_keys configuration option, potentially disclosing passwords to unauthorized actors.
CVE-2019-16060 has a severity value of 9.8, which is considered critical.
The vulnerability affects Airbrake Ruby notifier 4.2.3. Versions 4.2.2 and earlier are unaffected.
To fix CVE-2019-16060, update to version 4.2.4 of the Airbrake Ruby notifier.
You can find more information about CVE-2019-16060 at the following link: [https://github.com/airbrake/airbrake-ruby/issues/468](https://github.com/airbrake/airbrake-ruby/issues/468)