Bugzilla – Bug 1227000
VUL-0: CVE-2024-3817: conftest: hashicorp/go-getter: argument injection when fetching remote default git branches
Last modified: 2024-06-26 09:21:11 UTC
openSUSE:Factory/conftest embeds hashicorp/go-getter: HashiCorp’s go-getter library is vulnerable to argument injection when executing Git to discover remote branches. This vulnerability does not affect the go-getter/v2 branch and package. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-3817 https://www.cve.org/CVERecord?id=CVE-2024-3817 https://discuss.hashicorp.com/t/hcsec-2024-09-hashicorp-go-getter-vulnerable-to-argument-injection-when-fetching-remote-default-git-branches/66040 https://bugzilla.redhat.com/show_bug.cgi?id=2275807
conftest 0.53.0 already includes the fixed go-getter library and is part of openSUSE:Factory https://github.com/open-policy-agent/conftest/commit/1b3cc13b4d5e8d99a7a124672046605d1c33d0bc https://build.opensuse.org/request/show/1180222 No change needed.
Nothing to do, closing.