Information Exposure Affecting github.com/hashicorp/go-getter/helper/url package, versions <1.5.11


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.04% (6th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMHASHICORPGOGETTERHELPERURL-2804031
  • published27 Apr 2022
  • disclosed27 Apr 2022
  • creditGuilherme Macedo

Introduced: 27 Apr 2022

CVE-2022-29810  (opens in a new tab)
CWE-200  (opens in a new tab)

How to fix?

Upgrade github.com/hashicorp/go-getter/helper/url to version 1.5.11 or higher.

Overview

github.com/hashicorp/go-getter/helper/url is a library for Go for downloading files or directories from various sources using a URL as the primary form of input.

Affected versions of this package are vulnerable to Information Exposure when it is writing SSH credentials into the log file, which leads to exposure of sensitive credentials to local users who are able to read the log file.

CVSS Scores

version 3.1