Executive brief
node-etsy-client is a Node.js library for integrating with the Etsy API. When a network connection error occurs, the library may leak the API key secret in error messages that are reported to end users or logged. An attacker with network access could intercept these error messages or observe logs to obtain API credentials, leading to unauthorized access to Etsy API functionality and potential data breach.
Technical details
This is an information disclosure vulnerability (CWE-200, CWE-209) in the error handling logic of node-etsy-client versions 0.2.0 and earlier. When a network connection error occurs during Etsy API communication, the error object containing the API key is passed directly to client error reporting or logging without sanitization. An authenticated user with network visibility or log access can extract the API key secret. The vulnerability affects all applications using node-etsy-client ≤0.2.0 that report or log client errors. The fix in v0.3.0 removes sensitive data from error messages before reporting them to end users.
Affected products
- creharmony node-etsy-client 0.2.0 and earlier
Timeline
- 2021-04-06: disclosed
- 2021-04-06: patched: Fixed in v0.3.0