CVE-2024-6104
EUVD-2024-217324.06.2024, 17:15
go-retryablehttp prior to 0.7.7 did not sanitize urls when writing them to its log file. This could lead to go-retryablehttp writing sensitive HTTP basic auth credentials to its log file. This vulnerability, CVE-2024-6104, was fixed in go-retryablehttp 0.7.7.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| hashicorp | retryablehttp | 𝑥 < 0.7.7 |
𝑥
= Vulnerable software versions
Debian Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cosign |
| ||||||||||||||||
| cosign-bash-completion |
| ||||||||||||||||
| cosign-zsh-completion |
| ||||||||||||||||
| podman |
| ||||||||||||||||
| podman-docker |
| ||||||||||||||||
| podman-remote |
| ||||||||||||||||
| podmansh |
| ||||||||||||||||
| rekor |
| ||||||||||||||||
| skopeo |
| ||||||||||||||||
| skopeo-bash-completion |
| ||||||||||||||||
| skopeo-zsh-completion |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||
|---|---|---|---|
| grafana |
| ||
| grafana-selinux |
| ||
| podman |
| ||
| podman-docker |
| ||
| podman-plugins |
| ||
| podman-remote |
| ||
| podman-tests |
| ||
| skopeo |
| ||
| skopeo-tests |
|
Common Weakness Enumeration