Intel

AIKIDO-2024-10113

github.com/hashicorp/go-retryablehttp is vulnerable to Insertion of Sensitive Information into Log File

Insertion of Sensitive Information into Log FileCVE-2024-6104 Published May 31, 2024

50

Medium Risk

This Affects:

gogithub.com/hashicorp/go-retryablehttp
0.7.3 - 0.7.6
Fixed in 0.7.7
Are you affected? Scan for Free

TL;DR

Affected versions of the go-retryablehttp package could potentially log URL-embedded basic authentication credentials in the logs.

Who does this affect?

You are affected if you use the go-retryablehttp package.

Background info

github.com/hashicorp/go-retryablehttp is vulnerable to Insertion of Sensitive Information into Log File in versions 0.7.3 - 0.7.6.

How to fix this

Upgrade github.com/hashicorp/go-retryablehttp to the patch version (version 0.7.7).