Executive brief
loguru is a Python logging library widely used to capture application events and troubleshoot issues. A flaw in versions prior to 0.5.3 causes the library to inadvertently log sensitive information (such as credentials or API keys) in clear text, exposing confidential data if logs are accessed or stored insecurely. This could lead to unauthorized access to systems or services if logged secrets are compromised.
Technical details
loguru prior to version 0.5.3 improperly handles sensitive information, logging it in plaintext where it should be redacted or masked. This is an insertion of sensitive information into log files vulnerability (CWE-532). The issue affects all previous versions up through 0.5.2. The attack vector is network-based with low complexity, and requires authenticated access. An attacker with access to application logs could extract sensitive credentials or secrets to compromise systems. The vulnerability was patched in version 0.5.3 via commit ea39375, which documents security considerations and best practices.
Affected products
- loguru loguru 0.5.2 and earlier
Timeline
- 2022-01-26: disclosed
- 2022-01-26: patched: Fixed in version 0.5.3