Bugzilla – Bug 1227023
VUL-0: CVE-2023-0475: TRACKERBUG: hashicorp/go-getter: denial of service via malicious compressed archive
Last modified: 2024-06-26 09:00:16 UTC
HashiCorp go-getter up to 1.6.2 and 2.1.1 is vulnerable to decompression bombs. Fixed in 1.7.0 and 2.2.0. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-0475 https://www.cve.org/CVERecord?id=CVE-2023-0475 https://discuss.hashicorp.com/t/hcsec-2023-4-go-getter-vulnerable-to-denial-of-service-via-malicious-compressed-archive/50125 https://bugzilla.redhat.com/show_bug.cgi?id=2170844 https://access.redhat.com/errata/RHSA-2023:2029.html
Nothing to do: - openSUSE:Factory/conftest github.com/hashicorp/go-getter (v1.7.3) - openSUSE:Factory/grype github.com/hashicorp/go-getter (v1.7.3) - openSUSE:Factory/helmfile github.com/hashicorp/go-getter (v1.7.3) - openSUSE:Factory/k9s github.com/hashicorp/go-getter (v1.7.3) - openSUSE:Factory/kubescape github.com/hashicorp/go-getter (v1.7.3) - openSUSE:Factory/minikube github.com/hashicorp/go-getter (v1.7.3) - openSUSE:Factory/okteto github.com/hashicorp/go-getter (v1.7.3) - openSUSE:Factory/opentofu github.com/hashicorp/go-getter (v1.7.3) - openSUSE:Factory/talosctl github.com/hashicorp/go-getter/v2 (v2.2.1) - openSUSE:Factory/terragrunt github.com/hashicorp/go-getter (v1.7.1) - openSUSE:Factory/terragrunt github.com/hashicorp/go-getter/v2 (v2.2.1) - openSUSE:Factory/trivy github.com/hashicorp/go-getter (v1.7.3)