Information on source package golang-github-hashicorp-go-getter

Available versions

ReleaseVersion
bullseye1.4.1-1
bookworm1.4.1-1
sid1.4.1-1

Open issues

BugbullseyebookwormsidDescription
CVE-2024-6257vulnerable (no DSA)vulnerable (no DSA)vulnerableHashiCorp\u2019s go-getter library can be coerced into executing Git u ...
CVE-2024-3817vulnerable (no DSA)vulnerable (no DSA)vulnerableHashiCorp\u2019s go-getter library is vulnerable to argument injection ...
CVE-2023-0475vulnerable (no DSA)vulnerable (no DSA)vulnerableHashiCorp go-getter up to 1.6.2 and 2.1.1 is vulnerable to decompressi ...
CVE-2022-30323vulnerable (no DSA)vulnerable (no DSA)vulnerablego-getter up to 1.5.11 and 2.0.2 panicked when processing password-pro ...
CVE-2022-30322vulnerable (no DSA)vulnerable (no DSA)vulnerablego-getter up to 1.5.11 and 2.0.2 allowed asymmetric resource exhaustio ...
CVE-2022-30321vulnerable (no DSA)vulnerable (no DSA)vulnerablego-getter up to 1.5.11 and 2.0.2 allowed arbitrary host access via go- ...
CVE-2022-26945vulnerable (no DSA)vulnerable (no DSA)vulnerablego-getter up to 1.5.11 and 2.0.2 allowed protocol switching, endless r ...

Resolved issues

BugDescription
CVE-2022-29810The Hashicorp go-getter library before 1.5.11 does not redact an SSH k ...

Search for package or bug name: Reporting problems