Description
The Hashicorp go-getter library before 1.5.11 does not redact an SSH key from a URL query parameter.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-1591 | The Hashicorp go-getter library before 1.5.11 does not redact an SSH key from a URL query parameter. |
Github GHSA |
GHSA-27rq-4943-qcwp | Insertion of Sensitive Information into Log File in Hashicorp go-getter |
References
History
Sun, 08 Sep 2024 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:acm:2.4::el8 cpe:/a:redhat:acm:2.5::el8 |
Mon, 19 Aug 2024 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:acm:2.5::el8 |
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-03T06:33:42.774Z
Reserved: 2022-04-27T00:00:00.000Z
Link: CVE-2022-29810
No data.
Status : Modified
Published: 2022-04-27T06:15:40.247
Modified: 2024-11-21T06:59:43.553
Link: CVE-2022-29810
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA