The getter package can write SSH credentials to its logfile, exposing credentials to local users able to read the logfile.
{ "url": "https://pkg.go.dev/vuln/GO-2022-0438", "review_status": "REVIEWED" }
{ "imports": [ { "symbols": [ "Client.ChecksumFromFile", "Client.Get", "FolderStorage.Get", "Get", "GetAny", "GetFile", "HttpGetter.Get", "RedactURL" ], "path": "github.com/hashicorp/go-getter" } ] }