CVE-2022-39292 HIGH

CVE-2022-39292: Exposure of sensitive Slack webhook URLs in debug logs and traces

Vendor Abdolence
Product slack-morphism-rust
Weakness CWE-1258
Published October 10, 2022
Last update April 23, 2025

CVSS base score

7.5/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

What the vulnerability does

01Description

Slack Morphism is a modern client library for Slack Web/Events API/Socket Mode and Block Kit. Debug logs expose sensitive URLs for Slack webhooks that contain private information. The problem is fixed in version 1.3.2 which redacts sensitive URLs for webhooks. As a workaround, people who use Slack webhooks may disable or filter debug logs.

Key dates

02Disclosure timeline

October 10, 2022 CVE published
April 23, 2025 Record updated