github.com/hashicorp/go-retryablehttp is vulnerable to Insertion of Sensitive Information into Log File
50
Medium Risk
Affected versions of the go-retryablehttp package could potentially log URL-embedded basic authentication credentials in the logs.
You are affected if you use the go-retryablehttp package.
github.com/hashicorp/go-retryablehttp is vulnerable to Insertion of Sensitive Information into Log File in versions 0.7.3 - 0.7.6.
Upgrade github.com/hashicorp/go-retryablehttp to the patch version (version 0.7.7).
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant