Description
Shared Access Signature token is not masked in the backup configuration response and is also exposed in the yb_backup logs
Problem types
CWE-532 Insertion of Sensitive Information into Log File
Product status
2.20.0.0 before 2.20.7.0
2.23.0.0 before 2.23.1.0
2024.1.0.0 before 2024.1.3.0
References
docs.yugabyte.com/...secure/vulnerability-disclosure-policy/