First published: Mon Jun 24 2024(Updated: )
go-retryablehttp prior to 0.7.7 did not sanitize urls when writing them to its log file. This could lead to go-retryablehttp writing sensitive HTTP basic auth credentials to its log file. This vulnerability, <a href="https://access.redhat.com/security/cve/CVE-2024-6104">CVE-2024-6104</a>, was fixed in go-retryablehttp 0.7.7. <a href="https://discuss.hashicorp.com/c/security">https://discuss.hashicorp.com/c/security</a>
Credit: security@hashicorp.com security@hashicorp.com
Affected Software | Affected Version | How to fix |
---|---|---|
Hashicorp Retryablehttp Go | <0.7.7 | |
go/github.com/hashicorp/go-retryablehttp | <0.7.7 | 0.7.7 |
redhat/go-retryablehttp | <0.7.7 | 0.7.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.