VDB
Sign up
—

GO-2023-1578

Denial of service in github.com/hashicorp/go-getter/v2

Quick fix

GO-2023-1578 — github.com/hashicorp/go-getter/v2: upgrade to the fixed version with the command below.

go get github.com/hashicorp/go-getter/v2@v2.2.0

Details

HashiCorp go-getter is vulnerable to decompression bombs. This can lead to excessive memory consumption and denial-of-service attacks.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/hashicorp/go-getter/v2
Introduced in: 2.0.0Fixed in: 2.2.0
Fixgo get github.com/hashicorp/go-getter/v2@v2.2.0
Go/github.com/hashicorp/go-getter
Introduced in: 0Fixed in: 1.7.0
Fixgo get github.com/hashicorp/go-getter@v1.7.0

References