MEDIUMNuGet

Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error

Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error

CVE-2024-40636Published 2 years agoUpdated 5 days agoSource: OSV

Affected packages

  • Steeltoe.Discovery.ClientAutofacall versions
  • Steeltoe.Discovery.ClientCoreall versions
  • Steeltoe.Discovery.Eurekabefore 3.2.8
  • Steeltoe.Discovery.EurekaBaseall versions

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
EPSS percentile

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.

Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error | HackTribune