github.com/hashicorp/go-getter is vulnerable to Insertion of Sensitive Information into Log File
9
Low Risk
Affected versions of this package may expose SSH keys in log files when multiple keys are included in the URL (e.g., ssh://git@github.com/hashicorp/go-getter-test-private.git?sshkey=secretkey&sshkey=secretkey). This flaw can lead to sensitive credential leakage.
You are affected if you are using a vulnerable version of the package.
github.com/hashicorp/go-getter is vulnerable to Insertion of Sensitive Information into Log File in versions 1.0.0 - 1.7.8.
Upgrade github.com/hashicorp/go-getter to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant