Home
LOW: 3.2 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:NDefault status
unaffected
Any version before 0.4.0rc3
affected
Description
Llama Stack (aka llama-stack) before 0.4.0rc3 does not censor the pgvector password in the initialization log.
Problem types
CWE-532 Insertion of Sensitive Information into Log File
Product status
Any version before 0.4.0rc3
References
github.com/llamastack/llama-stack/pull/4439
github.com/...tack/llama-stack/compare/v0.4.0rc2...v0.4.0rc3