We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
Para is a multitenant backend server/framework for object persistence and retrieval. A vulnerability that exists in versions prior to 1.50.8 in `FacebookAuthFilter.java` results in a full request URL being logged during a failed request to a Facebook user profile. The log includes the user's access token in plain text. Since WARN-level logs are often retained in production and accessible to operators or log aggregation systems, this poses a risk of token exposure. Version 1.50.8 fixes the issue.
Reserved 2025-05-29 | Published 2025-06-05 | Updated 2025-06-05 | Assigner GitHub_MCWE-532: Insertion of Sensitive Information into Log File
github.com/...a/para/security/advisories/GHSA-qx7g-fx8q-545g
github.com/...ommit/46a908d887da02037384193f70a69345f04887cf
Support options