CVE-2022-29810: Insertion of Sensitive Information into Log File in Hashicorp go-getter
(updated )
The Hashicorp go-getter library before 1.5.11 could write SSH credentials into its logfile, exposing sensitive credentials to local users able to read the logfile.
References
Detect and mitigate CVE-2022-29810 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →