The getter package can write SSH credentials to its logfile, exposing credentials to local users able to read the logfile.
{ "review_status": "REVIEWED", "url": "https://pkg.go.dev/vuln/GO-2022-0438" }
{ "imports": [ { "path": "github.com/hashicorp/go-getter", "symbols": [ "Client.ChecksumFromFile", "Client.Get", "FolderStorage.Get", "Get", "GetAny", "GetFile", "HttpGetter.Get", "RedactURL" ] } ] }