Lack of data validation - Path Traversal In github.com/hashicorp/go-getter/gcs/v2
Description
HashiCorp go-getter unsafe downloads could lead to arbitrary host access HashiCorp go-getter through 2.0.2 does not safely perform downloads. Arbitrary host access was possible via go-getter path traversal, symlink processing, and command injection flaws.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
go | 2.1.0 | ||
debian 11 | - | ||
go | 1.6.1, 2.1.0 | ||
go | 2.1.0 | ||
go | 2.1.0 | ||
debian 12 | - |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3. 4. 5. 6. 7. 8. 9.