github.com/hashicorp/go-retryablehttp is vulnerable to Insertion of Sensitive Information into Log File
50
Medium Risk
Affected versions of the go-retryablehttp package could potentially log URL-embedded basic authentication credentials in the logs.
You are affected if you use the go-retryablehttp package.
github.com/hashicorp/go-retryablehttp is vulnerable to Insertion of Sensitive Information into Log File in versions 0.7.3 - 0.7.6.
Upgrade github.com/hashicorp/go-retryablehttp to the patch version (version 0.7.7).
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant