First published: Wed Apr 27 2022(Updated: )
A flaw was found in go-getter, where the go-getter library can write SSH credentials into its log file. This flaw allows a local user with access to read log files to read sensitive credentials, which may lead to privilege escalation or account takeover.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HashiCorp go-getter | <1.5.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2022-29810 is a vulnerability in the Hashicorp go-getter library before 1.5.11 that does not redact an SSH key from a URL query parameter.
The severity of CVE-2022-29810 is medium with a severity value of 5.1.
CVE-2022-29810 affects the Hashicorp go-getter library before 1.5.11 and the HashiCorp go-getter package with versions up to 1.5.11.
The impact of CVE-2022-29810 is that a local user with access to read log files may be able to read sensitive credentials, potentially leading to privilege escalation or account takeover.
To fix CVE-2022-29810, update the Hashicorp go-getter library to version 1.5.11 or later.