Github.com/go-viper/mapstructure/v2: go-viper's mapstructure may leak sensitive information in logs in github.com/go-viper/mapstructure
A flaw was found in github.com/go-viper/mapstructure/v2, in the field processing component using mapstructure.WeakDecode. This vulnerability allows information disclosure through detailed error messages that may leak sensitive input values via malformed user-supplied data processed in security-critical contexts.
Affected products
- <2.4.0
Matching in nixpkgs
pkgs.podman
Program for managing pods, containers and container images
pkgs.toolbox
Tool for containerized command line environments on Linux
pkgs.bctoolbox
Utilities library for Linphone
pkgs.lttoolbox
Finite state compiler, processor and helper tools used by apertium
pkgs.openshift
Build, deploy, and manage your applications with Docker and Kubernetes
pkgs.devtoolbox
Development tools at your fingertips
pkgs.podman-tui
Podman Terminal UI
pkgs.podman-bootc
Streamlining podman+bootc interactions
pkgs.podman-compose
Implementation of docker-compose with podman backend
pkgs.podman-desktop
A graphical tool for developing on containers and Kubernetes
pkgs.tlaplusToolbox
IDE for the TLA+ tools
pkgs.jetbrains-toolbox
Jetbrains Toolbox
-
nixos-unstable 3.1.0.62320
- nixpkgs-unstable 3.1.0.62320
- nixos-unstable-small 3.1.0.62320
-
nixos-25.05 2.6.1.40902
- nixos-25.05-small 2.6.1.40902
- nixpkgs-25.05-darwin 2.6.1.40902
pkgs.nltk-data.toolbox
NLTK Data
-
nixos-unstable 0-unstable-2024-07-29
- nixpkgs-unstable 0-unstable-2024-07-29
- nixos-unstable-small 0-unstable-2024-07-29
pkgs.headphones-toolbox
UI for configuring Ploopy Headphones
pkgs.nomad-driver-podman
Podman task driver for Nomad
pkgs.perlPackages.TestToolbox
Test::Toolbox - tools for testing
pkgs.python312Packages.podman
Python bindings for Podman's RESTful API
pkgs.python313Packages.podman
Python bindings for Podman's RESTful API
pkgs.linphonePackages.bctoolbox
Utilities library for Linphone
pkgs.perl538Packages.TestToolbox
Test::Toolbox - tools for testing
pkgs.perl540Packages.TestToolbox
Test::Toolbox - tools for testing
pkgs.python312Packages.openshift
Python client for the OpenShift API
pkgs.python313Packages.openshift
Python client for the OpenShift API
pkgs.python312Packages.mpltoolbox
Interactive tools for Matplotlib
pkgs.python313Packages.mpltoolbox
Interactive tools for Matplotlib
pkgs.haskellPackages.pdf-toolbox-core
A collection of tools for processing PDF files
pkgs.python312Packages.python-toolbox
Tools for testing PySnooper
pkgs.python312Packages.sphinx-toolbox
Box of handy tools for Sphinx
-
nixos-unstable -
- nixos-unstable-small 4.0.0
pkgs.python313Packages.python-toolbox
Tools for testing PySnooper
pkgs.python313Packages.sphinx-toolbox
Box of handy tools for Sphinx
-
nixos-unstable -
- nixos-unstable-small 4.0.0
pkgs.haskellPackages.pdf-toolbox-content
A collection of tools for processing PDF files
pkgs.haskellPackages.pdf-toolbox-document
A collection of tools for processing PDF files
pkgs.python312Packages.azure-mgmt-redhatopenshift
Microsoft Azure Red Hat Openshift Management Client Library for Python
Package maintainers
-
@jluttine Jaakko Luttinen <jaakko.luttinen@iki.fi>
-
@7c6f434c Michael Raskin <7c6f434c@mail.ru>
-
@Aleksanaa Aleksana QwQ <me@aleksana.moe>
-
@svelterust Knarkzel <knarkzel@gmail.com>
-
@flacks Jean Lucas <jean@4ray.co>
-
@nyabinary Niko Cantero <nyanbinary@keemail.me>
-
@AnatolyPopov Anatolii Popov <aipopov@live.ru>
-
@onthestairs Austin Platt <austinplatt@gmail.com>
-
@cpcloud Phillip Cloud
-
@stehessel Stephan Heßelmann <stephan@stehessel.de>
-
@moretea Maarten Hoogendoorn <maarten@moretea.nl>
-
@offlinehacker Jaka Hudoklin <jaka@x-truder.net>
-
@saschagrunert Sascha Grunert <mail@saschagrunert.de>
-
@vdemeester Vincent Demeester <vincent@sbr.pm>
-
@evan-goode Evan Goode <mail@evangoo.de>
-
@sikmir Nikolay Korotkiy <sikmir@disroot.org>
-
@booxter Ihar Hrachyshka <ihar.hrachyshka@gmail.com>
-
@aaronjheng Aaron Jheng <wentworth@outlook.com>
-
@teto Matthieu Coudron <mcoudron@hotmail.com>
-
@fabaff Fabian Affolter <mail@fabian-affolter.ch>
-
@seqizz Gurkan Gur <seqizz@gmail.com>
-
@urandom2 Colin Arnott <colin@urandom.co.uk>
-
@Naxdy Naxdy <naxdy@naxdy.org>
-
@happysalada Raphael Megzari <raphael@megzari.com>
-
@bengsparks Ben Sparks <benjamin.sparks@protonmail.com>
-
@doronbehar Doron Behar <me@doronbehar.com>