CVE Vulnerabilities

CVE-2023-0475

Improper Handling of Highly Compressed Data (Data Amplification)

Published: Feb 16, 2023 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
4.2 MODERATE
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

HashiCorp go-getter up to 1.6.2 and 2.1.1 is vulnerable to decompression bombs. Fixed in 1.7.0 and 2.2.0.

Weakness

The product does not handle or incorrectly handles a compressed input with a very high compression ratio that produces a large output.

Affected Software

Name Vendor Start Version End Version
Go-getter Hashicorp * 1.6.2 (including)
Go-getter Hashicorp 2.1.1 (including) 2.1.1 (including)
Golang-github-hashicorp-go-getter Ubuntu bionic *
Golang-github-hashicorp-go-getter Ubuntu kinetic *
Golang-github-hashicorp-go-getter Ubuntu lunar *
Golang-github-hashicorp-go-getter Ubuntu mantic *
Golang-github-hashicorp-go-getter Ubuntu trusty *
Golang-github-hashicorp-go-getter Ubuntu xenial *
Red Hat OpenShift Container Platform 4.14 RedHat openshift4/ose-installer:v4.14.0-202310201027.p0.g03546e5.assembly.stream *
Red Hat OpenShift Security Profiles Operator stable on RHEL-8 RedHat compliance/openshift-security-profiles-rhel8-operator:0.7.1-3 *

References