Slack · Slack Morphism · CVE-2022-39292
**Name of the Vulnerable Software and Affected Versions**
Slack Morphism versions prior to 1.3.2
**Description**
The issue is related to the exposure of sensitive information in debug logs. Specifically, debug logs may contain sensitive URLs for Slack webhooks that include private information. This could allow a remote attacker to gain unauthorized access to protected information.
**Recommendations**
For versions prior to 1.3.2, update to version 1.3.2, which redacts sensitive URLs for webhooks.
As a temporary workaround, consider disabling or filtering debug logs, especially when using Slack webhooks, by adjusting the tracing log level and filters.