Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-6257

Опубликовано: 25 июн. 2024
Источник: debian
EPSS Низкий

Описание

HashiCorp’s go-getter library can be coerced into executing Git update on an existing maliciously modified Git Configuration, potentially leading to arbitrary code execution.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-github-hashicorp-go-getterunfixedpackage
golang-github-hashicorp-go-getterno-dsabookwormpackage
golang-github-hashicorp-go-getterno-dsabullseyepackage

Примечания

  • https://discuss.hashicorp.com/t/hcsec-2024-13-hashicorp-go-getter-vulnerable-to-code-execution-on-git-update-via-git-config-manipulation/68081

EPSS

Процентиль: 28%
0.00095
Низкий

Связанные уязвимости

CVSS3: 8.4
ubuntu
около 1 года назад

HashiCorp’s go-getter library can be coerced into executing Git update on an existing maliciously modified Git Configuration, potentially leading to arbitrary code execution.

CVSS3: 7.7
redhat
около 1 года назад

HashiCorp’s go-getter library can be coerced into executing Git update on an existing maliciously modified Git Configuration, potentially leading to arbitrary code execution.

CVSS3: 8.4
nvd
около 1 года назад

HashiCorp’s go-getter library can be coerced into executing Git update on an existing maliciously modified Git Configuration, potentially leading to arbitrary code execution.

CVSS3: 8.4
msrc
11 месяцев назад

Описание отсутствует

CVSS3: 8.4
redos
10 месяцев назад

Уязвимость terraform

EPSS

Процентиль: 28%
0.00095
Низкий