—
GO-2023-1578
Denial of service in github.com/hashicorp/go-getter/v2
Quick fix
GO-2023-1578 — github.com/hashicorp/go-getter/v2: upgrade to the fixed version with the command below.
go get github.com/hashicorp/go-getter/v2@v2.2.0Details
HashiCorp go-getter is vulnerable to decompression bombs. This can lead to excessive memory consumption and denial-of-service attacks.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/hashicorp/go-getter/v2
Introduced in:
2.0.0Fixed in: 2.2.0Fix
go get github.com/hashicorp/go-getter/v2@v2.2.0Go/github.com/hashicorp/go-getter
Introduced in:
0Fixed in: 1.7.0Fix
go get github.com/hashicorp/go-getter@v1.7.0References
- https://discuss.hashicorp.com/t/hcsec-2023-4-go-getter-vulnerable-to-denial-of-service-via-malicious-compressed-archive/50125[WEB]
- https://github.com/hashicorp/go-getter/commit/0edab85348271c843782993345b07b1ac98912e6[FIX]
- https://github.com/hashicorp/go-getter/commit/78e6721a2a76266718dc92c3c03c1571dffdefdc[FIX]