Description
HashiCorp go-slug up to 0.4.3 did not fully protect against directory traversal while unpacking tar archives, and protections could be bypassed with specific constructions of multiple symlinks. Fixed in 0.5.0.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0600 | HashiCorp go-slug up to 0.4.3 did not fully protect against directory traversal while unpacking tar archives, and protections could be bypassed with specific constructions of multiple symlinks. Fixed in 0.5.0. |
Github GHSA |
GHSA-2g5j-5x95-r6hr | Unsafe tar unpacking in HashiCorp go-slug |
References
History
Sun, 08 Sep 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat
Redhat acm |
|
| CPEs | cpe:/a:redhat:acm:2.2::el7 | |
| Vendors & Products |
Redhat
Redhat acm |
Mon, 19 Aug 2024 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:acm:2.2::el8 |
|
| Vendors & Products |
Redhat
Redhat acm |
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T16:55:10.521Z
Reserved: 2020-12-03T00:00:00.000Z
Link: CVE-2020-29529
No data.
Status : Modified
Published: 2020-12-03T20:15:11.820
Modified: 2024-11-21T05:24:09.323
Link: CVE-2020-29529
OpenCVE Enrichment
No data.
EUVD
Github GHSA