HashiCorp go-slug up to 0.4.3 did not fully protect against directory traversal while unpacking tar archives, and protections could be bypassed with specific constructions of multiple symlinks. Fixed in 0.5.0.
History

Sun, 08 Sep 2024 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat acm
CPEs cpe:/a:redhat:acm:2.2::el7
Vendors & Products Redhat
Redhat acm

Mon, 19 Aug 2024 22:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:acm:2.2::el7
cpe:/a:redhat:acm:2.2::el8
Vendors & Products Redhat
Redhat acm

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2020-12-03T19:04:50

Updated: 2024-08-04T16:55:10.521Z

Reserved: 2020-12-03T00:00:00

Link: CVE-2020-29529

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-12-03T20:15:11.820

Modified: 2021-03-08T13:22:17.247

Link: CVE-2020-29529

cve-icon Redhat

Severity : Moderate

Publid Date: 2020-12-03T00:00:00Z

Links: CVE-2020-29529 - Bugzilla