logo

Database

Excessive privileges In github.com/hashicorp/go-getter/v2

Description

Data Amplification in HashiCorp go-getter HashiCorp go-getter up to 1.6.2 and 2.1.1 is vulnerable to decompression bombs. Fixed in 1.7.0 and 2.2.0.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions
FLAT-19K4E – Vulnerability | Fluid Attacks Database