Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown

CVE-2022-26945

Disclosure Date: May 25, 2022 (last updated October 07, 2023)
go-getter up to 1.5.11 and 2.0.2 allowed protocol switching, endless redirect, and configuration bypass via abuse of custom HTTP response header processing. Fixed in 1.6.1 and 2.1.0.
Attacker Value
Unknown

CVE-2022-30323

Disclosure Date: May 25, 2022 (last updated November 29, 2024)
go-getter up to 1.5.11 and 2.0.2 panicked when processing password-protected ZIP files. Fixed in 1.6.1 and 2.1.0.
Attacker Value
Unknown

CVE-2022-30321

Disclosure Date: May 25, 2022 (last updated February 23, 2025)
go-getter up to 1.5.11 and 2.0.2 allowed arbitrary host access via go-getter path traversal, symlink processing, and command injection flaws. Fixed in 1.6.1 and 2.1.0.
Attacker Value
Unknown

CVE-2022-30322

Disclosure Date: May 25, 2022 (last updated November 29, 2024)
go-getter up to 1.5.11 and 2.0.2 allowed asymmetric resource exhaustion when go-getter processed malicious HTTP responses. Fixed in 1.6.1 and 2.1.0.