Описание
Insertion of Sensitive Information into Log File in Hashicorp go-getter
The Hashicorp go-getter library before 1.5.11 could write SSH credentials into its logfile, exposing sensitive credentials to local users able to read the logfile.
Пакеты
Наименование
github.com/hashicorp/go-getter
go
Затронутые версииВерсия исправления
< 1.5.11
1.5.11
Связанные уязвимости
CVSS3: 5.1
redhat
больше 3 лет назад
The Hashicorp go-getter library before 1.5.11 does not redact an SSH key from a URL query parameter.
CVSS3: 5.5
nvd
больше 3 лет назад
The Hashicorp go-getter library before 1.5.11 does not redact an SSH key from a URL query parameter.
CVSS3: 5.5
debian
больше 3 лет назад
The Hashicorp go-getter library before 1.5.11 does not redact an SSH k ...