Excessive privileges In golang-github-hashicorp-go-getter
Description
Data Amplification in HashiCorp go-getter HashiCorp go-getter up to 1.6.2 and 2.1.1 is vulnerable to decompression bombs. Fixed in 1.7.0 and 2.2.0.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 11 | - | ||
go | 1.7.0 | ||
go | 2.2.0 | ||
debian 12 | - |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3.