{"id":"CVE-2022-31162","aliases":["GHSA-99j7-mhfh-w84p","RUSTSEC-2022-0086"],"url":"https://o3.security/vulnerability/CVE-2022-31162","summary":"Slack Morphism for Rust before 0.41.0 can accidentally leak Slack OAuth client information in application debug logs","details":"### Impact\nPotential/accidental leaking of Slack OAuth client information in application debug logs.\n\n### Patches\nMore strict and secure debug formatting was introduced in v0.41 for OAuth secret types to avoid the possibility of printing sensitive information in application logs.\n\n### Workarounds\nDon't print/output in logs request and responses for OAuth and client configurations.\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in the [repo](https://github.com/abdolence/slack-morphism-rust)\n* Email us at [me@abdolence.dev](mailto:me@abdolence.dev)\n","published":"2022-07-21T13:20:12Z","modified":"2026-08-12T03:51:18.446538831Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"slack-morphism","fixedVersion":"0.41.0"}],"fix":{"url":"https://github.com/abdolence/slack-morphism-rust/pull/133","label":"abdolence/slack-morphism-rust#133"},"references":[{"type":"WEB","url":"https://github.com/abdolence/slack-morphism-rust/releases/tag/v0.41.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/31xxx/CVE-2022-31162.json"},{"type":"ADVISORY","url":"https://github.com/abdolence/slack-morphism-rust/security/advisories/GHSA-99j7-mhfh-w84p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-31162"},{"type":"WEB","url":"https://github.com/abdolence/slack-morphism-rust/pull/133"},{"type":"WEB","url":"https://github.com/abdolence/slack-morphism-rust/commit/4923fb7d458ed28c0302244c54cb4df0acee7ee6"},{"type":"PACKAGE","url":"https://github.com/abdolence/slack-morphism-rust"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2022-0086.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:18.446538831Z"}}