Описание
HashiCorp’s go-getter library can be coerced into executing Git update on an existing maliciously modified Git Configuration, potentially leading to arbitrary code execution.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Trusted Application Pipeline | rhtap-contract-tenant/cli-v01 | Will not fix | ||
| Red Hat Trusted Application Pipeline | rhtap-contract-tenant/cli-v02 | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.7 High
CVSS3
Связанные уязвимости
HashiCorp’s go-getter library can be coerced into executing Git update on an existing maliciously modified Git Configuration, potentially leading to arbitrary code execution.
HashiCorp’s go-getter library can be coerced into executing Git update on an existing maliciously modified Git Configuration, potentially leading to arbitrary code execution.
HashiCorp go-getter Vulnerable to Code Execution On Git Update Via Git Config Manipulation
HashiCorp\u2019s go-getter library can be coerced into executing Git u ...
HashiCorp go-getter Vulnerable to Code Execution On Git Update Via Git Config Manipulation
EPSS
7.7 High
CVSS3