RADAR-base / radar-output-restructure

Reads avro files in HDFS and outputs json or csv per topic per user in local file system
Apache License 2.0
1 stars 0 forks source link

Information Exposure SNYK-JAVA-IOPROJECTREACTORNETTY-3057195 #535

Closed github-actions[bot] closed 1 year ago

github-actions[bot] commented 2 years ago

Overview

Affected versions of this package are vulnerable to Information Exposure due to logging request headers in some cases of invalid HTTP requests. The logged headers may reveal valid access tokens to those with access to server logs.

Note:

This vulnerability affects only invalid HTTP requests where logging at WARN level is enabled.

Remediation

Upgrade io.projectreactor.netty:reactor-netty-http to version 1.0.24 or higher.

References