Impact
The go-getter library is vulnerable in its handling of archive decompression up to versions 1.8.8 and 2.2.3. A crafted archive can cause extracted files to be created with elevated permission bits the extraction, a local attacker could cause files to be written with those higher privileges, allowing the attacker to obtain the extracting process’s permissions.
Affected Systems
The vulnerability affects HashiCorp’s shared go-getter library in the versions listed above. Organizations using any of these releases should verify whether they rely on the go-getter archive extraction routine in a privileged context.
Risk and Exploitability
The CVSS score of 6.7 indicates a moderate severity, while the EPSS score of less than 1% suggests low likelihood of exploitation in the current environment. The issue is not listed in the CISA KEV catalog. Exploitation requires local access to a system where a privileged user runs go-getter to extract an archive. A crafted archive is the main vector, and the problem arises when decompression writes files with elevated permission bits, enabling privilege escalation.
OpenCVE Enrichment