HashiCorp go-slug up to 0.4.3 did not fully protect against directory traversal while unpacking tar archives, and protections could be bypassed with specific constructions of multiple symlinks. Fixed in 0.5.0.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2023-0600 | HashiCorp go-slug up to 0.4.3 did not fully protect against directory traversal while unpacking tar archives, and protections could be bypassed with specific constructions of multiple symlinks. Fixed in 0.5.0. |
![]() |
GHSA-2g5j-5x95-r6hr | Unsafe tar unpacking in HashiCorp go-slug |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 08 Sep 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Redhat
Redhat acm |
|
CPEs | cpe:/a:redhat:acm:2.2::el7 | |
Vendors & Products |
Redhat
Redhat acm |
Mon, 19 Aug 2024 22:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:/a:redhat:acm:2.2::el8 |
|
Vendors & Products |
Redhat
Redhat acm |

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T16:55:10.521Z
Reserved: 2020-12-03T00:00:00
Link: CVE-2020-29529

No data.

Status : Modified
Published: 2020-12-03T20:15:11.820
Modified: 2024-11-21T05:24:09.323
Link: CVE-2020-29529


No data.