The Hashicorp go-getter library before 1.5.11 could write SSH credentials into its logfile, exposing sensitive credentials to local users able to read the logfile.
References:- https://nvd.nist.gov/vuln/detail/CVE-2022-29810
- https://github.com/hashicorp/go-getter/pull/348
- https://github.com/hashicorp/go-getter/commit/36b68b2f68a3ed10ee7ecbb0cb9f6b1dc5da49cc
- https://github.com/hashicorp/go-getter/releases/tag/v1.5.11
- https://pkg.go.dev/vuln/GO-2022-0438
- https://github.com/advisories/GHSA-27rq-4943-qcwp