URLs were not sanitized when writing them to log files. This could lead to writing sensitive HTTP basic auth credentials to the log file.
{ "review_status": "REVIEWED", "url": "https://pkg.go.dev/vuln/GO-2024-2947" }
{ "imports": [ { "path": "github.com/hashicorp/go-retryablehttp", "symbols": [ "Client.Do", "Client.Get", "Client.Head", "Client.Post", "Client.PostForm", "Get", "Head", "Post", "PostForm", "RoundTripper.RoundTrip" ] } ] }