Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-8959

Опубликовано: 15 авг. 2025
Источник: debian
EPSS Низкий

Описание

HashiCorp's go-getter library subdirectory download feature is vulnerable to symlink attacks leading to unauthorized read access beyond the designated directory boundaries. This vulnerability, identified as CVE-2025-8959, is fixed in go-getter 1.7.9.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-github-hashicorp-go-getterremovedpackage
golang-github-hashicorp-go-getterignoredbookwormpackage
golang-github-hashicorp-go-getterpostponedbullseyepackage

Примечания

  • https://discuss.hashicorp.com/t/hcsec-2025-23-hashicorp-go-getter-vulnerable-to-arbitrary-read-through-symlink-attack/76242

EPSS

Процентиль: 6%
0.00024
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
6 месяцев назад

HashiCorp's go-getter library subdirectory download feature is vulnerable to symlink attacks leading to unauthorized read access beyond the designated directory boundaries. This vulnerability, identified as CVE-2025-8959, is fixed in go-getter 1.7.9.

CVSS3: 7.5
redhat
6 месяцев назад

HashiCorp's go-getter library subdirectory download feature is vulnerable to symlink attacks leading to unauthorized read access beyond the designated directory boundaries. This vulnerability, identified as CVE-2025-8959, is fixed in go-getter 1.7.9.

CVSS3: 7.5
nvd
6 месяцев назад

HashiCorp's go-getter library subdirectory download feature is vulnerable to symlink attacks leading to unauthorized read access beyond the designated directory boundaries. This vulnerability, identified as CVE-2025-8959, is fixed in go-getter 1.7.9.

CVSS3: 7.5
github
6 месяцев назад

HashiCorp go-getter Vulnerable to Symlink Attacks

CVSS3: 7.5
fstec
6 месяцев назад

Уязвимость библиотеки Go Getter, связанная с некорректным определением символических ссылок перед доступом к файлу, позволяющая нарушителю получить несанкционированный доступ на чтение защищаемой информации

EPSS

Процентиль: 6%
0.00024
Низкий