The Hashicorp go-getter library before 1.5.11 does not redact an SSH key from a URL query parameter.
                
            Metrics
No CVSS v4.0
Attack Vector Local
Attack Complexity Low
Privileges Required Low
Scope Unchanged
Confidentiality Impact High
Integrity Impact None
Availability Impact None
User Interaction None
No CVSS v3.0
Access Vector Local
Access Complexity Low
Authentication None
Confidentiality Impact Partial
Integrity Impact None
Availability Impact None
This CVE is not in the KEV list.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
| Vendors | Products | 
|---|---|
| Hashicorp | 
 | 
| Redhat | 
 | 
| Package | CPE | Advisory | Released Date | 
|---|---|---|---|
| Red Hat Advanced Cluster Management for Kubernetes 2 | |||
| acm-grafana-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| acm-must-gather-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| acm-operator-bundle-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| application-ui-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| assisted-image-service-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| cert-policy-controller-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| cluster-backup-operator-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| clusterclaims-controller-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| cluster-curator-controller-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| clusterlifecycle-state-metrics-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| cluster-proxy-addon-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| config-policy-controller-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| console-api-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| console-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| discovery-operator-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| endpoint-monitoring-operator-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| governance-policy-propagator-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| governance-policy-spec-sync-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| governance-policy-status-sync-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| governance-policy-template-sync-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| grafana-dashboard-loader-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| grc-ui-api-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| grc-ui-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| iam-policy-controller-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| insights-client-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| insights-metrics-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| klusterlet-addon-controller-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| klusterlet-addon-operator-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| kube-rbac-proxy-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| kube-state-metrics-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| managedcluster-import-controller-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| management-ingress-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| memcached-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| memcached-exporter-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| metrics-collector-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| multicloud-integrations-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| multicloud-manager-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| multiclusterhub-operator-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| multiclusterhub-repo-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| multicluster-observability-operator-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| multicluster-operators-application-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| multicluster-operators-channel-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| multicluster-operators-deployable-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| multicluster-operators-placementrule-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| multicluster-operators-subscription-operator-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| multicluster-operators-subscription-release-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| node-exporter-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| observatorium-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| observatorium-operator-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| openshift-hive-operator-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| placement-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| prometheus-alertmanager-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| prometheus-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| provider-credential-controller-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| rbac-query-proxy-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| redisgraph-tls-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| registration-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| registration-operator-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| rhacm-agent-service-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| rhacm-assisted-installer-agent-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| rhacm-assisted-installer-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| rhacm-assisted-installer-reporter-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| search-aggregator-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| search-api-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| search-collector-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| search-operator-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| search-ui-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| submariner-addon-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| thanos-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| thanos-receive-controller-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| volsync-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| volsync-mover-rclone-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| volsync-mover-restic-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| volsync-mover-rsync-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| work-container | cpe:/a:redhat:acm:2.4::el8 | RHSA-2022:5201 | 2022-06-27T00:00:00Z | 
| acm-cluster-proxy-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| acm-governance-policy-addon-controller-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| acm-grafana-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| acm-must-gather-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| acm-operator-bundle-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| acm-prometheus-config-reloader-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| acm-prometheus-operator-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| acm-volsync-addon-controller-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| cert-policy-controller-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| cluster-backup-operator-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| cluster-proxy-addon-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| config-policy-controller-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| console-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| endpoint-monitoring-operator-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| governance-policy-propagator-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| governance-policy-spec-sync-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| governance-policy-status-sync-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| governance-policy-template-sync-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| grafana-dashboard-loader-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| iam-policy-controller-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| insights-client-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| insights-metrics-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| klusterlet-addon-controller-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| klusterlet-addon-operator-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| kube-rbac-proxy-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| kube-state-metrics-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| management-ingress-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| memcached-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| memcached-exporter-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| metrics-collector-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| multicloud-integrations-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| multiclusterhub-operator-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| multiclusterhub-repo-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| multicluster-observability-operator-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| multicluster-operators-application-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| multicluster-operators-channel-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| multicluster-operators-subscription-operator-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| node-exporter-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| observatorium-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| observatorium-operator-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| prometheus-alertmanager-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| prometheus-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| rbac-query-proxy-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| redisgraph-tls-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| search-aggregator-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| search-api-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| search-collector-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| search-operator-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| submariner-addon-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| thanos-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| thanos-receive-controller-container | cpe:/a:redhat:acm:2.5::el8 | RHSA-2022:4956 | 2022-06-09T00:00:00Z | 
| Red Hat Advanced Cluster Management for Kubernetes 2.3 for RHEL 8 | |||
| rhacm2/cluster-curator-controller-rhel8:v2.3.11-5 | cpe:/a:redhat:acm:2.3::el8 | RHSA-2022:5392 | 2022-06-28T00:00:00Z | 
| Red Hat OpenShift Container Platform 4.11 | |||
| openshift4/ose-baremetal-machine-controllers:v4.11.0-202208020235.p0.ga65be86.assembly.stream | cpe:/a:redhat:openshift:4.11::el8 | RHSA-2022:5069 | 2022-08-10T00:00:00Z | 
| openshift4/ose-baremetal-rhel8-operator:v4.11.0-202208020235.p0.g22b522c.assembly.stream | cpe:/a:redhat:openshift:4.11::el8 | RHSA-2022:5069 | 2022-08-10T00:00:00Z | 
| openshift4/ose-cluster-baremetal-operator-rhel8:v4.11.0-202208020235.p0.g0f415d1.assembly.stream | cpe:/a:redhat:openshift:4.11::el8 | RHSA-2022:5069 | 2022-08-10T00:00:00Z | 
| Red Hat OpenShift Data Foundation 4.11 on RHEL8 | |||
| odf4/odr-rhel8-operator:v4.11.0-27 | cpe:/a:redhat:openshift_data_foundation:4.11::el8 | RHSA-2022:6156 | 2022-08-24T00:00:00Z | 
References
        History
                    Sun, 08 Sep 2024 18:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| CPEs | cpe:/a:redhat:acm:2.4::el8 cpe:/a:redhat:acm:2.5::el8 | 
Mon, 19 Aug 2024 22:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| CPEs | cpe:/a:redhat:acm:2.5::el8 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: mitre
Published: 2022-04-27T05:50:30
Updated: 2024-08-03T06:33:42.774Z
Reserved: 2022-04-27T00:00:00
Link: CVE-2022-29810
 Vulnrichment
                        Vulnrichment
                    No data.
 NVD
                        NVD
                    Status : Modified
Published: 2022-04-27T06:15:40.247
Modified: 2024-11-21T06:59:43.553
Link: CVE-2022-29810
 Redhat
                        Redhat