The Hashicorp go-getter library before 1.5.11 does not redact an SSH key from a URL query parameter.
The product writes sensitive information to a log file.
Link | Tags |
---|---|
https://github.com/hashicorp/go-getter/pull/348 | patch third party advisory |
https://github.com/hashicorp/go-getter/releases/tag/v1.5.11 | release notes third party advisory |
https://github.com/hashicorp/go-getter/commit/36b68b2f68a3ed10ee7ecbb0cb9f6b1dc5da49cc | patch third party advisory |