Skip to content

Upgrade go-retryablehttp to 0.7.7#33

Merged
samstarling merged 2 commits intomasterfrom
sam/upgrade-go-retryablehttp
Feb 24, 2025
Merged

Upgrade go-retryablehttp to 0.7.7#33
samstarling merged 2 commits intomasterfrom
sam/upgrade-go-retryablehttp

Conversation

@samstarling
Copy link
Contributor

go-retryablehttp prior to 0.7.7 did not sanitize URLs when writing them to its log file. This could lead to go-retryablehttp writing sensitive HTTP basic auth credentials to its log file. This vulnerability, CVE-2024-6104, was fixed in go-retryablehttp 0.7.7.

go-retryablehttp prior to 0.7.7 did not sanitize URLs when writing them
to its log file. This could lead to go-retryablehttp writing sensitive
HTTP basic auth credentials to its log file. This vulnerability,
CVE-2024-6104, was fixed in go-retryablehttp 0.7.7.
@samstarling samstarling force-pushed the sam/upgrade-go-retryablehttp branch from d7db227 to b4ee406 Compare February 21, 2025 16:10
@samstarling samstarling merged commit 994268a into master Feb 24, 2025
1 check passed
@samstarling samstarling deleted the sam/upgrade-go-retryablehttp branch February 24, 2025 15:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

Comments