VDB
Sign up
LOW2.0

GHSA-j5vm-7qcc-2wwg

Kopia: Storage connection credentials written to console on "repository status" CLI command with JSON output

Quick fix

GHSA-j5vm-7qcc-2wwg — github.com/kopia/kopia: upgrade to the fixed version with the command below.

go get github.com/kopia/kopia@v0.16.0

Details

### Impact

_What kind of vulnerability is it? Who is impacted?_

Storage credentials are written to the console.

### Patches

_Has the problem been patched?_ Yes, see #3589 _What versions should users upgrade to?_ - Any version after or including commit 1d6f852cd6534f4bea978cbdc85c583803d79f77 - No release has been created yet.

### Workarounds _Is there a way for users to fix or remediate the vulnerability without upgrading?_

- Be aware that `kopia repo status --json` will write the credentials to the output without scrubbing them. - Avoid executing `kopia repo status` with the `--json` flag in an insecure environment where. - Avoid logging the output of the `kopia repo status --json` command.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/kopia/kopia
Introduced in: 0Fixed in: 0.16.0
Fixgo get github.com/kopia/kopia@v0.16.0

References