Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v6v8-xj6m-xwqh

Опубликовано: 24 июн. 2024
Источник: github
Github: Прошло ревью
CVSS3: 6

Описание

go-retryablehttp can leak basic auth credentials to log files

go-retryablehttp prior to 0.7.7 did not sanitize urls when writing them to its log file. This could lead to go-retryablehttp writing sensitive HTTP basic auth credentials to its log file. This vulnerability, CVE-2024-6104, was fixed in go-retryablehttp 0.7.7.

Пакеты

Наименование

github.com/hashicorp/go-retryablehttp

go
Затронутые версииВерсия исправления

< 0.7.7

0.7.7

EPSS

Процентиль: 1%
0.00009
Низкий

6 Medium

CVSS3

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 6
ubuntu
12 месяцев назад

go-retryablehttp prior to 0.7.7 did not sanitize urls when writing them to its log file. This could lead to go-retryablehttp writing sensitive HTTP basic auth credentials to its log file. This vulnerability, CVE-2024-6104, was fixed in go-retryablehttp 0.7.7.

CVSS3: 6
redhat
12 месяцев назад

go-retryablehttp prior to 0.7.7 did not sanitize urls when writing them to its log file. This could lead to go-retryablehttp writing sensitive HTTP basic auth credentials to its log file. This vulnerability, CVE-2024-6104, was fixed in go-retryablehttp 0.7.7.

CVSS3: 6
nvd
12 месяцев назад

go-retryablehttp prior to 0.7.7 did not sanitize urls when writing them to its log file. This could lead to go-retryablehttp writing sensitive HTTP basic auth credentials to its log file. This vulnerability, CVE-2024-6104, was fixed in go-retryablehttp 0.7.7.

CVSS3: 5.5
msrc
9 месяцев назад

Описание отсутствует

CVSS3: 6
debian
12 месяцев назад

go-retryablehttp prior to 0.7.7 did not sanitize urls when writing the ...

EPSS

Процентиль: 1%
0.00009
Низкий

6 Medium

CVSS3

Дефекты

CWE-532