CVE-2023-30610

aws-sigv4 is a rust library for low level request signing in the aws cloud platform. The `aws_sigv4::SigningParams` struct had a derived `Debug` implementation. When debug-formatted, it would include a user's AWS access key, AWS secret key, and security token in plaintext. When TRACE-level logging is enabled for an SDK, `SigningParams` is printed, thereby revealing those credentials to anyone with access to logs. All users of the AWS SDK for Rust who enabled TRACE-level logging, either globally (e.g. `RUST_LOG=trace`), or for the `aws-sigv4` crate specifically are affected. This issue has been addressed in a set of new releases. Users are advised to upgrade. Users unable to upgrade should disable TRACE-level logging for AWS Rust SDK crates.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
GitHub_MCNA
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVEADP
---
---
CISA-ADPADP
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 23%
VendorProductVersion
amazonaws-sigv4
0.2.0
amazonaws-sigv4
0.3.0
amazonaws-sigv4
0.4.1
amazonaws-sigv4
0.5.2
amazonaws-sigv4
0.6.0
amazonaws-sigv4
0.7.0
amazonaws-sigv4
0.8.0
amazonaws-sigv4
0.9.0
amazonaws-sigv4
0.10.1
amazonaws-sigv4
0.11.0
amazonaws-sigv4
0.12.0
amazonaws-sigv4
0.13.0
amazonaws-sigv4
0.14.0
amazonaws-sigv4
0.15.0
amazonaws-sigv4
0.46.0
amazonaws-sigv4
0.47.0
amazonaws-sigv4
0.48.0
amazonaws-sigv4
0.49.0
amazonaws-sigv4
0.50.0
amazonaws-sigv4
0.51.0
amazonaws-sigv4
0.52.0
amazonaws-sigv4
0.53.1
amazonaws-sigv4
0.54.1
amazonaws-sigv4
0.55.0
𝑥
= Vulnerable software versions