Sensitive information in source code In github.com/hashicorp/go-getter
Description
Insertion of Sensitive Information into Log File in Hashicorp go-getter The Hashicorp go-getter library before 1.5.11 could write SSH credentials into its logfile, exposing sensitive credentials to local users able to read the logfile.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
go | 1.5.11 |
Aliases
1. 2. 3. 4.
References
1. 2. 3. 4.