Bugzilla – Bug 1227006
VUL-0: CVE-2024-3817: okteto: hashicorp/go-getter: argument injection when fetching remote default git branches
Last modified: 2024-06-26 09:15:07 UTC
openSUSE:Factory/okteto embeds hashicorp/go-getter: HashiCorp’s go-getter library is vulnerable to argument injection when executing Git to discover remote branches. This vulnerability does not affect the go-getter/v2 branch and package. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-3817 https://www.cve.org/CVERecord?id=CVE-2024-3817 https://discuss.hashicorp.com/t/hcsec-2024-09-hashicorp-go-getter-vulnerable-to-argument-injection-when-fetching-remote-default-git-branches/66040 https://bugzilla.redhat.com/show_bug.cgi?id=2275807