Vulnerability Report: GO-2024-2947
- CVE-2024-6104, GHSA-v6v8-xj6m-xwqh
- Affects: github.com/hashicorp/go-retryablehttp
- Published: Jun 25, 2024
URLs were not sanitized when writing them to log files. This could lead to writing sensitive HTTP basic auth credentials to the log file.
For detailed information about this vulnerability, visit https://github.com/advisories/GHSA-v6v8-xj6m-xwqh.
Affected Packages
-
PathGo VersionsSymbols
-
before v0.7.7
Aliases
References
- https://github.com/advisories/GHSA-v6v8-xj6m-xwqh
- https://github.com/hashicorp/go-retryablehttp/commit/a99f07beb3c5faaa0a283617e6eb6bcf25f5049a
- https://discuss.hashicorp.com/t/hcsec-2024-12-go-retryablehttp-can-leak-basic-auth-credentials-to-log-files/68027
- https://vuln.go.dev/ID/GO-2024-2947.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.