Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2g5j-5x95-r6hr

Опубликовано: 06 фев. 2023
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Unsafe tar unpacking in HashiCorp go-slug

HashiCorp go-slug before 0.5.0 does not address attempts at directory traversal involving ../ and symlinks.

Пакеты

Наименование

github.com/hashicorp/go-slug

go
Затронутые версииВерсия исправления

< 0.5.0

0.5.0

EPSS

Процентиль: 76%
0.00982
Низкий

7.5 High

CVSS3

Дефекты

CWE-22
CWE-59

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 4 лет назад

HashiCorp go-slug up to 0.4.3 did not fully protect against directory traversal while unpacking tar archives, and protections could be bypassed with specific constructions of multiple symlinks. Fixed in 0.5.0.

CVSS3: 7.5
redhat
больше 4 лет назад

HashiCorp go-slug up to 0.4.3 did not fully protect against directory traversal while unpacking tar archives, and protections could be bypassed with specific constructions of multiple symlinks. Fixed in 0.5.0.

CVSS3: 7.5
nvd
больше 4 лет назад

HashiCorp go-slug up to 0.4.3 did not fully protect against directory traversal while unpacking tar archives, and protections could be bypassed with specific constructions of multiple symlinks. Fixed in 0.5.0.

CVSS3: 7.5
debian
больше 4 лет назад

HashiCorp go-slug up to 0.4.3 did not fully protect against directory ...

EPSS

Процентиль: 76%
0.00982
Низкий

7.5 High

CVSS3

Дефекты

CWE-22
CWE-59