The Hashicorp go-getter library before 1.5.11 does not redact an SSH key from a URL query parameter.
The product writes sensitive information to a log file.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Go-getter | Hashicorp | * | 1.5.11 (excluding) |
| Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8 | RedHat | rhacm2/cluster-curator-controller-rhel8:v2.3.11-5 | * |
| Red Hat OpenShift Container Platform 4.11 | RedHat | openshift4/ose-baremetal-machine-controllers:v4.11.0-202208020235.p0.ga65be86.assembly.stream | * |
| Red Hat OpenShift Container Platform 4.11 | RedHat | openshift4/ose-baremetal-rhel8-operator:v4.11.0-202208020235.p0.g22b522c.assembly.stream | * |
| Red Hat OpenShift Container Platform 4.11 | RedHat | openshift4/ose-cluster-baremetal-operator-rhel8:v4.11.0-202208020235.p0.g0f415d1.assembly.stream | * |
| Red Hat OpenShift Data Foundation 4.11 on RHEL8 | RedHat | odf4/odr-rhel8-operator:v4.11.0-27 | * |