Description
All versions of snyk-broker before 4.73.1 are vulnerable to Information Exposure. It logs private keys if logging level is set to DEBUG.
Remediation
References
https://snyk.io/vuln/SNYK-JS-SNYKBROKER-570613
https://updates.snyk.io/snyk-broker-security-fixes-152338
Related Vulnerabilities
CVE-2021-23353 Vulnerability in maven package org.webjars:jspdf
CVE-2023-36542 Vulnerability in maven package org.apache.nifi:nifi-hbase_2-client-service
CVE-2020-10968 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2022-1295 Vulnerability in maven package org.webjars.bower:fullpage.js