Описание
HashiCorp’s go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operations through a maliciously crafted URL. This vulnerability, CVE-2026-4660, is fixed in go-getter v1.8.6. This vulnerability does not affect the go-getter/v2 branch and package.
A flaw was found in the go-getter library. A remote attacker could exploit this vulnerability by providing a maliciously crafted URL during certain git operations. This could allow the attacker to perform arbitrary file reads on the file system, potentially leading to the disclosure of sensitive information.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenShift Container Platform 4 | redhat-user-workloads/art-images | Affected | ||
| Red Hat Trusted Artifact Signer | redhat-user-workloads/cli-v06 | Not affected | ||
| Red Hat Trusted Artifact Signer | redhat-user-workloads/cli-v08 | Affected | ||
| Red Hat Trusted Artifact Signer 1.3 | rhtas/client-server-rhel9 | Fixed | RHSA-2026:24478 | 08.06.2026 |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
HashiCorp’s go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operations through a maliciously crafted URL. This vulnerability, CVE-2026-4660, is fixed in go-getter v1.8.6. This vulnerability does not affect the go-getter/v2 branch and package.
HashiCorp’s go-getter library up to v1.8.5 may allow arbitrary file reads on the file system during certain git operations through a maliciously crafted URL. This vulnerability, CVE-2026-4660, is fixed in go-getter v1.8.6. This vulnerability does not affect the go-getter/v2 branch and package.
HashiCorp\u2019s go-getter library up to v1.8.5 may allow arbitrary fi ...
HashiCorp's go-getter library may allow arbitrary file reads
7.5 High
CVSS3