VDB
Sign up
—

GO-2022-0438

Exposure of sensitive information via log file in github.com/hashicorp/go-getter

Quick fix

GO-2022-0438 — github.com/hashicorp/go-getter: upgrade to the fixed version with the command below.

go get github.com/hashicorp/go-getter@v1.5.11

Details

The getter package can write SSH credentials to its logfile, exposing credentials to local users able to read the logfile.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/hashicorp/go-getter
Introduced in: 0Fixed in: 1.5.11
Fixgo get github.com/hashicorp/go-getter@v1.5.11

References