Description
The Hashicorp go-getter library before 1.5.11 does not redact an SSH key from a URL query parameter.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6Attack Vector: Local
Complexity: Low
Privileges: Low
User Interaction: None
Scope: Unchanged
Confidentiality: High
Integrity: None
Availability: None
Affected Packages3 packages
🔴Vulnerability Details
6OSVExposure of sensitive information via log file in github.com/hashicorp/go-getter↗2022-07-01 ▶ GHSAInsertion of Sensitive Information into Log File in Hashicorp go-getter↗2022-04-28 ▶ OSVInsertion of Sensitive Information into Log File in Hashicorp go-getter↗2022-04-28 ▶ OSVExposure of SSH credentials in Rancher/Fleet↗2022-04-27 ▶ CVEListCVE-2022-29810: The Hashicorp go-getter library before 1↗2022-04-27 ▶ 📋Vendor Advisories
2Red Hatgo-getter: writes SSH credentials into logfile, exposing sensitive credentials to local uses↗2022-04-27 ▶ DebianCVE-2022-29810: golang-github-hashicorp-go-getter - The Hashicorp go-getter library before 1.5.11 does not redact an SSH key from a ...↗2022 ▶