Bugzilla – Bug 1227002
VUL-0: CVE-2024-3817: helmfile: hashicorp/go-getter: argument injection when fetching remote default git branches
Last modified: 2024-06-27 15:37:06 UTC
openSUSE:Factory/helmfile embeds hashicorp/go-getter: HashiCorp’s go-getter library is vulnerable to argument injection when executing Git to discover remote branches. This vulnerability does not affect the go-getter/v2 branch and package. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-3817 https://www.cve.org/CVERecord?id=CVE-2024-3817 https://discuss.hashicorp.com/t/hcsec-2024-09-hashicorp-go-getter-vulnerable-to-argument-injection-when-fetching-remote-default-git-branches/66040 https://bugzilla.redhat.com/show_bug.cgi?id=2275807
Fixed with: https://build.opensuse.org/request/show/1183440 See also: https://github.com/helmfile/helmfile/commit/ad0ef709e955640531ba2118a41c856dae638e81
SR https://build.opensuse.org/request/show/1183440 has been accepted, so the next openSUSE:Factory build will contain a fixed version of helmfile.