HashiCorp go-slug up to 0.4.3 did not fully protect against directory traversal while unpacking tar archives, and protections could be bypassed with specific constructions of multiple symlinks. Fixed in 0.5.0.
Metrics
Affected Vendors & Products
References
History
Sun, 08 Sep 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Redhat
Redhat acm |
|
CPEs | cpe:/a:redhat:acm:2.2::el7 | |
Vendors & Products |
Redhat
Redhat acm |
Mon, 19 Aug 2024 22:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:/a:redhat:acm:2.2::el8 |
|
Vendors & Products |
Redhat
Redhat acm |
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-12-03T19:04:50
Updated: 2024-08-04T16:55:10.521Z
Reserved: 2020-12-03T00:00:00
Link: CVE-2020-29529
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-12-03T20:15:11.820
Modified: 2024-11-21T05:24:09.323
Link: CVE-2020-29529
Redhat