Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown

CVE-2023-0475

Disclosure Date: February 16, 2023 (last updated October 08, 2023)
HashiCorp go-getter up to 1.6.2 and 2.1.1 is vulnerable to decompression bombs. Fixed in 1.7.0 and 2.2.0.
Attacker Value
Unknown

CVE-2022-26945

Disclosure Date: May 25, 2022 (last updated October 07, 2023)
go-getter up to 1.5.11 and 2.0.2 allowed protocol switching, endless redirect, and configuration bypass via abuse of custom HTTP response header processing. Fixed in 1.6.1 and 2.1.0.
Attacker Value
Unknown

CVE-2022-30323

Disclosure Date: May 25, 2022 (last updated November 29, 2024)
go-getter up to 1.5.11 and 2.0.2 panicked when processing password-protected ZIP files. Fixed in 1.6.1 and 2.1.0.
Attacker Value
Unknown

CVE-2022-30321

Disclosure Date: May 25, 2022 (last updated February 23, 2025)
go-getter up to 1.5.11 and 2.0.2 allowed arbitrary host access via go-getter path traversal, symlink processing, and command injection flaws. Fixed in 1.6.1 and 2.1.0.
Attacker Value
Unknown

CVE-2022-30322

Disclosure Date: May 25, 2022 (last updated November 29, 2024)
go-getter up to 1.5.11 and 2.0.2 allowed asymmetric resource exhaustion when go-getter processed malicious HTTP responses. Fixed in 1.6.1 and 2.1.0.
Attacker Value
Unknown

CVE-2022-29810

Disclosure Date: April 27, 2022 (last updated February 23, 2025)
The Hashicorp go-getter library before 1.5.11 does not redact an SSH key from a URL query parameter.