Description
All versions of snyk-broker before 4.73.1 are vulnerable to Information Exposure. It logs private keys if logging level is set to DEBUG.
Remediation
References
https://snyk.io/vuln/SNYK-JS-SNYKBROKER-570613
https://updates.snyk.io/snyk-broker-security-fixes-152338
Related Vulnerabilities
CVE-2023-44487 Vulnerability in maven package org.apache.tomcat:tomcat-coyote
CVE-2023-50771 Vulnerability in maven package org.jenkins-ci.plugins:oic-auth
CVE-2013-7315 Vulnerability in maven package org.springframework:spring-web
CVE-2023-50778 Vulnerability in maven package com.cloudtp.jenkins:paaslane-estimate