github.com
https://github.com/abdolence/slack-morphism-rust CVE-2022-39292
HIGH
Exposure of sensitive Slack webhook URLs in debug logs and traces
Record summary
CVE-2022-39292 has a selected CVSS score of 7.5 (high).
Description
Slack Morphism is a modern client library for Slack Web/Events API/Socket Mode and Block Kit. Debug logs expose sensitive URLs for Slack webhooks that contain private information. The problem is fixed in version 1.3.2 which redacts sensitive URLs for webhooks. As a workaround, people who use Slack webhooks may disable or filter debug logs.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 23, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
slack-morphism-rustBrowse abdolence / slack-morphism-rust | CVE List | <= 1.3.0 | affected |
slack-morphismBrowse crates.io / slack-morphism | GitHub Advisory | Before 1.3.2 · Fixed in 1.3.2 | affected |
References
7github.com
https://github.com/abdolence/slack-morphism-rust/commit/48a1da2dc2ad3a5ccc60036d43f6f8fbb2c15f1d github.com
https://github.com/abdolence/slack-morphism-rust/commit/65ef9fac4f39c4e171e2952a6cf029bb0d059a89 github.com
https://github.com/abdolence/slack-morphism-rust/releases/tag/v1.3.2 github.com
https://github.com/abdolence/slack-morphism-rust/security/advisories/GHSA-4mjx-2gh5-ph8h nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-39292 rustsec.org
https://rustsec.org/advisories/RUSTSEC-2022-0087.html