Description
All versions of snyk-broker before 4.73.1 are vulnerable to Information Exposure. It logs private keys if logging level is set to DEBUG.
Remediation
References
https://snyk.io/vuln/SNYK-JS-SNYKBROKER-570613
https://updates.snyk.io/snyk-broker-security-fixes-152338
Related Vulnerabilities
CVE-2023-27094 Vulnerability in maven package cn.hippo4j:hippo4j-all
CVE-2020-15270 Vulnerability in npm package parse-server
CVE-2019-10745 Vulnerability in npm package assign-deep
CVE-2021-21118 Vulnerability in maven package org.webjars.npm:electron
CVE-2020-36048 Vulnerability in maven package org.webjars.bower:engine.io