Unknown API tokens get logged in plain text
Package
rudder-jetty
(rudder)
Affected versions
*
Patched versions
None
rudder-webapp
(rudder)
< 8.1.8
8.1.8
Impact
When making a call to the Rudder HTTP API with token unknown the application, the raw value gets logged at warning level:
There is no immediate impact for the target Rudder server as the token is invalid, but it could be valid elsewhere (another Rudder server, etc.)
Patches
Workarounds
None.
References