Описание
go-getter up to 1.5.11 and 2.0.2 panicked when processing password-protected ZIP files. Fixed in 1.6.1 and 2.1.0.
Ссылки
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Release NotesThird Party Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Release NotesThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.5.11 (включая)
Одно из
cpe:2.3:a:hashicorp:go-getter:*:*:*:*:*:*:*:*
cpe:2.3:a:hashicorp:go-getter:2.0.2:*:*:*:*:*:*:*
EPSS
Процентиль: 49%
0.00255
Низкий
8.6 High
CVSS3
7.5 High
CVSS2
Дефекты
NVD-CWE-noinfo
Связанные уязвимости
CVSS3: 8.6
ubuntu
около 3 лет назад
go-getter up to 1.5.11 and 2.0.2 panicked when processing password-protected ZIP files. Fixed in 1.6.1 and 2.1.0.
CVSS3: 8.6
redhat
около 3 лет назад
go-getter up to 1.5.11 and 2.0.2 panicked when processing password-protected ZIP files. Fixed in 1.6.1 and 2.1.0.
CVSS3: 8.6
debian
около 3 лет назад
go-getter up to 1.5.11 and 2.0.2 panicked when processing password-pro ...
CVSS3: 8.6
github
около 3 лет назад
HashiCorp go-getter unsafe downloads could lead to asymmetric resource exhaustion
EPSS
Процентиль: 49%
0.00255
Низкий
8.6 High
CVSS3
7.5 High
CVSS2
Дефекты
NVD-CWE-noinfo