HIGH8.6
GHSA-28r2-q6m8-9hpx
HashiCorp go-getter unsafe downloads could lead to asymmetric resource exhaustion
Quick fix
GHSA-28r2-q6m8-9hpx — github.com/hashicorp/go-getter: upgrade to the fixed version with the command below.
go get github.com/hashicorp/go-getter@v1.6.1Details
HashiCorp go-getter through 2.0.2 does not safely perform downloads. Asymmetric resource exhaustion could occur when go-getter processed malicious HTTP responses.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/hashicorp/go-getter
Introduced in:
0Fixed in: 1.6.1Fix
go get github.com/hashicorp/go-getter@v1.6.1Go/github.com/hashicorp/go-getter
Introduced in:
2.0.0Fixed in: 2.1.0Fix
go get github.com/hashicorp/go-getter@v2.1.0Go/github.com/hashicorp/go-getter/v2
Introduced in:
0Fixed in: 2.1.0Fix
go get github.com/hashicorp/go-getter/v2@v2.1.0Go/github.com/hashicorp/go-getter/s3/v2
Introduced in:
0Fixed in: 2.1.0Fix
go get github.com/hashicorp/go-getter/s3/v2@v2.1.0Go/github.com/hashicorp/go-getter/gcs/v2
Introduced in:
0Fixed in: 2.1.0Fix
go get github.com/hashicorp/go-getter/gcs/v2@v2.1.0References
- https://nvd.nist.gov/vuln/detail/CVE-2022-30323[ADVISORY]
- https://github.com/hashicorp/go-getter/pull/359[WEB]
- https://github.com/hashicorp/go-getter/pull/361[WEB]
- https://github.com/hashicorp/go-getter/commit/38e97387488f5439616be60874979433a12edb48[WEB]
- https://github.com/hashicorp/go-getter/commit/a2ebce998f8d4105bd4b78d6c99a12803ad97a45[WEB]
- https://discuss.hashicorp.com[WEB]
- https://discuss.hashicorp.com/t/hcsec-2022-13-multiple-vulnerabilities-in-go-getter-library[WEB]
- https://discuss.hashicorp.com/t/hcsec-2022-13-multiple-vulnerabilities-in-go-getter-library/39930[WEB]
- https://github.com/hashicorp/go-getter[PACKAGE]
- https://github.com/hashicorp/go-getter/releases[WEB]
- https://pkg.go.dev/vuln/GO-2022-0586[WEB]