First published: Mon Jun 24 2024(Updated: )
go-retryablehttp could allow a local authenticated attacker to obtain sensitive information, caused by the failure to sanitize urls when writing them to its log file. An attacker could exploit this vulnerability to write sensitive HTTP basic auth credentials to its log file.
Credit: security@hashicorp.com security@hashicorp.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hashicorp Retryablehttp Go | <0.7.7 | |
go/github.com/hashicorp/go-retryablehttp | <0.7.7 | 0.7.7 |
redhat/go-retryablehttp | <0.7.7 | 0.7.7 |
IBM Concert Software | <=1.0.0, 1.0.1, 1.0.2, 1.0.2.1, 1.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.