Description
All versions of snyk-broker before 4.73.1 are vulnerable to Information Exposure. It logs private keys if logging level is set to DEBUG.
Remediation
References
https://snyk.io/vuln/SNYK-JS-SNYKBROKER-570613
https://updates.snyk.io/snyk-broker-security-fixes-152338
Related Vulnerabilities
CVE-2020-6426 Vulnerability in maven package org.webjars.npm:electron
CVE-2019-10754 Vulnerability in maven package org.apereo.cas:cas-server-support-oauth-core-api
CVE-2022-31167 Vulnerability in maven package org.xwiki.platform:xwiki-platform-security
CVE-2020-28052 Vulnerability in maven package bouncycastle:bcprov-jdk14
CVE-2018-11039 Vulnerability in maven package org.springframework:spring-web