CVE-2019-16060: Critical severity airbrake vulnerability
The Airbrake Ruby notifier 4.2.3 for Airbrake mishandles the blacklistkeys configuration option and consequently may disclose passwords to unauthorized actors. This is fixed in 4.2.4 (also, 4.2.2 and earlier are unaffected).
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-16060?
CVE-2019-16060 is a vulnerability in the Airbrake Ruby notifier 4.2.3 that mishandles the blacklist_keys configuration option, potentially disclosing passwords to unauthorized actors.
How severe is CVE-2019-16060?
CVE-2019-16060 has a severity value of 9.8, which is considered critical.
Which software versions are affected by CVE-2019-16060?
The vulnerability affects Airbrake Ruby notifier 4.2.3. Versions 4.2.2 and earlier are unaffected.
How can I fix CVE-2019-16060?
To fix CVE-2019-16060, update to version 4.2.4 of the Airbrake Ruby notifier.
Where can I find more information about CVE-2019-16060?
You can find more information about CVE-2019-16060 at the following link: [https://github.com/airbrake/airbrake-ruby/issues/468](https://github.com/airbrake/airbrake-ruby/issues/468)