getsentry / getsentry/sentry-javascript
Sensitive values bypass the denylist in header and cookie collection
Offen
javascript
- Vorherrschende Sprache
- TypeScript
- Sterne
- 8.7k
- Forks
- 1.8k
- Ø Merge
- 1 T. 17 Std.
- Gemergte PRs (30 T.)
- 523
Beschreibung
A cookie header that cannot be split into `name=value` pairs ends up verbatim in an attribute key, and headers listed in `headersToSpanAttributes` skip the denylist, so an `authorization` header is sent in the clear.
Beitragsleitfaden
Bewertung
Dieses Issue wurde noch nicht bewertet.