Description
All versions of snyk-broker before 4.73.1 are vulnerable to Information Exposure. It logs private keys if logging level is set to DEBUG.
Remediation
References
https://snyk.io/vuln/SNYK-JS-SNYKBROKER-570613
https://updates.snyk.io/snyk-broker-security-fixes-152338
Related Vulnerabilities
CVE-2023-37909 Vulnerability in maven package org.xwiki.platform:xwiki-platform-menu-ui
CVE-2019-18212 Vulnerability in maven package org.lsp4xml:lsp4xml-extensions
CVE-2023-29014 Vulnerability in maven package io.goobi.viewer:viewer-core
CVE-2023-40827 Vulnerability in maven package org.pf4j:pf4j
CVE-2021-21266 Vulnerability in maven package org.openhab.addons.bundles:org.openhab.binding.ihc