Improper resource allocation In github.com/hashicorp/go-getter
Description
HashiCorp go-getter unsafe downloads could lead to asymmetric resource exhaustion HashiCorp go-getter through 2.0.2 does not safely perform downloads. Asymmetric resource exhaustion could occur when go-getter processed malicious HTTP responses.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
go | 1.6.1, 2.1.0 | ||
go | 2.1.0 | ||
go | 2.1.0 | ||
go | 2.1.0 | ||
debian 11 | - | ||
debian 12 | - |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3. 4. 5. 6. 7. 8. 9.