HashiCorp go-getter up to 1.6.2 and 2.1.1 is vulnerable to decompression bombs. Fixed in 1.7.0 and 2.2.0.
The product does not handle or incorrectly handles a compressed input with a very high compression ratio that produces a large output.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Go-getter | Hashicorp | * | 1.6.2 (including) |
Go-getter | Hashicorp | 2.1.1 (including) | 2.1.1 (including) |
Golang-github-hashicorp-go-getter | Ubuntu | bionic | * |
Golang-github-hashicorp-go-getter | Ubuntu | kinetic | * |
Golang-github-hashicorp-go-getter | Ubuntu | lunar | * |
Golang-github-hashicorp-go-getter | Ubuntu | mantic | * |
Golang-github-hashicorp-go-getter | Ubuntu | trusty | * |
Golang-github-hashicorp-go-getter | Ubuntu | xenial | * |
Red Hat OpenShift Container Platform 4.14 | RedHat | openshift4/ose-installer:v4.14.0-202310201027.p0.g03546e5.assembly.stream | * |
Red Hat OpenShift Security Profiles Operator stable on RHEL-8 | RedHat | compliance/openshift-security-profiles-rhel8-operator:0.7.1-3 | * |