LOW 2.0 Go
Kopia: Storage connection credentials written to console on "repository status" CLI command with JSON output
GHSA-j5vm-7qcc-2wwg · GO-2024-2703
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Impact
What kind of vulnerability is it? Who is impacted?
Storage credentials are written to the console.
Patches
Has the problem been patched? Yes, see #3589
What versions should users upgrade to?
- Any version after or including commit 1d6f852cd6534f4bea978cbdc85c583803d79f77
- No release has been created yet.
Workarounds
Is there a way for users to fix or remediate the vulnerability without upgrading?
- Be aware that
kopia repo status --jsonwill write the credentials to the output without scrubbing them. - Avoid executing
kopia repo statuswith the--jsonflag in an insecure environment where. - Avoid logging the output of the
kopia repo status --jsoncommand.
Ready to move
Start Securing
Free, no credit card | First findings in minutes