CVE-2024-6104
24.06.2024, 17:15
go-retryablehttp prior to 0.7.7 did not sanitize urls when writing them to its log file. This could lead to go-retryablehttp writing sensitive HTTP basic auth credentials to its log file. This vulnerability, CVE-2024-6104, was fixed in go-retryablehttp 0.7.7.Enginsight
Vendor | Product | Version |
---|---|---|
hashicorp | retryablehttp | 𝑥 < 0.7.7 |
𝑥
= Vulnerable software versions

Debian Releases
Common Weakness Enumeration