CVE Vulnerabilities

CVE-2023-0475

Improper Handling of Highly Compressed Data (Data Amplification)

Published: Feb 16, 2023 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
4.2 MODERATE
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

HashiCorp go-getter up to 1.6.2 and 2.1.1 is vulnerable to decompression bombs. Fixed in 1.7.0 and 2.2.0.

Weakness

The product does not handle or incorrectly handles a compressed input with a very high compression ratio that produces a large output.

Affected Software

NameVendorStart VersionEnd Version
Go-getterHashicorp*1.6.2 (including)
Go-getterHashicorp2.1.1 (including)2.1.1 (including)
Red Hat OpenShift Container Platform 4.14RedHatopenshift4/ose-installer:v4.14.0-202310201027.p0.g03546e5.assembly.stream*
Golang-github-hashicorp-go-getterUbuntubionic*
Golang-github-hashicorp-go-getterUbuntuesm-apps/bionic*
Golang-github-hashicorp-go-getterUbuntuesm-apps/focal*
Golang-github-hashicorp-go-getterUbuntuesm-apps/jammy*
Golang-github-hashicorp-go-getterUbuntuesm-apps/noble*
Golang-github-hashicorp-go-getterUbuntufocal*
Golang-github-hashicorp-go-getterUbuntujammy*
Golang-github-hashicorp-go-getterUbuntukinetic*
Golang-github-hashicorp-go-getterUbuntulunar*
Golang-github-hashicorp-go-getterUbuntumantic*
Golang-github-hashicorp-go-getterUbuntunoble*
Golang-github-hashicorp-go-getterUbuntuoracular*
Golang-github-hashicorp-go-getterUbuntuplucky*
Golang-github-hashicorp-go-getterUbuntuquesting*
Golang-github-hashicorp-go-getterUbuntutrusty*
Golang-github-hashicorp-go-getterUbuntuupstream*
Golang-github-hashicorp-go-getterUbuntuxenial*
Golang-github-jesseduffield-go-getterUbuntuesm-apps/focal*
Golang-github-jesseduffield-go-getterUbuntuesm-apps/jammy*
Golang-github-jesseduffield-go-getterUbuntuesm-apps/noble*
Golang-github-jesseduffield-go-getterUbuntufocal*
Golang-github-jesseduffield-go-getterUbuntujammy*
Golang-github-jesseduffield-go-getterUbuntumantic*
Golang-github-jesseduffield-go-getterUbuntunoble*
Golang-github-jesseduffield-go-getterUbuntuoracular*

References