Server-side request forgery (SSRF) In golang-github-hashicorp-go-getter
Description
HashiCorp go-getter unsafe downloads HashiCorp go-getter through 2.0.2 does not safely perform downloads. Protocol switching, endless redirect, and configuration bypass were possible via abuse of custom HTTP response header processing.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 11 | - | ||
go | 2.1.0 | ||
debian 12 | - | ||
go | 1.6.1, 2.1.0 | ||
go | 2.1.0 | ||
go | 2.1.0 |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3. 4. 5. 6. 7. 8.