{"id":"GHSA-4g6q-77j7-vvjc","summary":"Logging of the firestore key within nodejs-firestore","details":"A potential logging of the firestore key via logging within nodejs-firestore exists - Developers who were logging objects through this._settings would be logging the firestore key as well potentially exposing it to anyone with logs read access. We recommend upgrading to version 6.1.0 to avoid this issue","aliases":["CVE-2023-6460"],"modified":"2026-05-08T20:49:06.546400Z","published":"2023-12-04T15:31:55Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2023-12-04T23:13:52Z","nvd_published_at":"2023-12-04T13:15:07Z","cwe_ids":["CWE-532","CWE-922"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-6460"},{"type":"WEB","url":"https://github.com/googleapis/nodejs-firestore/pull/1742"},{"type":"WEB","url":"https://bughunters.google.com/reports/vrp/KNvgo1Wij"},{"type":"PACKAGE","url":"https://github.com/googleapis/nodejs-firestore"},{"type":"WEB","url":"https://github.com/googleapis/nodejs-firestore/releases/tag/v6.1.0"}],"affected":[{"package":{"name":"@google-cloud/firestore","ecosystem":"npm","purl":"pkg:npm/%40google-cloud/firestore"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"6.1.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/12/GHSA-4g6q-77j7-vvjc/GHSA-4g6q-77j7-vvjc.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N"}]}