Private tokens could appear in logs if context containing gRPC metadata is logged in github.com/grpc/grpc-go
Description
### Impact This issue represents a potential PII concern. If applications were printing or logging a context containing gRPC metadata, the affected versions will contain all the metadata, which may include private information.
### Patches The issue first appeared in 1.64.0 and is patched in 1.64.1 and 1.65.0
### Workarounds If using an affected version and upgrading is not possible, ensuring you do not log or print contexts will avoid the problem.
Impact
Severity
help_outline
Latest version of the CVSS score reported by the source of the advisory.
LOW
Reference links
Summary
5.33k
Total packages affected
help_outline
Packages with at least one version that is affected by the advisory or has an affected dependency.
1.85k
Packages with a known fix
help_outline
Packages with versions affected by the advisory that have a greater version that is not affected.
0.40%
Total ecosystem affected
help_outline
The proportion of packages in the ecosystem that are affected by the advisory (fixed or not).
Affected Version: Introduced: 1.64.0, Fixed: 1.64.1
Patched/Unaffected
Affected