CVE-2023-0475Improper Handling of Highly Compressed Data (Data Amplification) in Hashicorp Go-getter

Severity
6.5MEDIUMNVD
CNA4.2
EPSS
0.1%
top 74.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 16
Latest updateFeb 17

Description

HashiCorp go-getter up to 1.6.2 and 2.1.1 is vulnerable to decompression bombs. Fixed in 1.7.0 and 2.2.0.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages4 packages

🔴Vulnerability Details

5
OSV
Denial of service in github.com/hashicorp/go-getter/v22023-02-17
OSV
CVE-2023-0475: HashiCorp go-getter up to 12023-02-16
CVEList
Go-Getter Vulnerable to Decompression Bombs2023-02-16
GHSA
Data Amplification in HashiCorp go-getter2023-02-16
OSV
Data Amplification in HashiCorp go-getter2023-02-16

📋Vendor Advisories

3
Red Hat
go-getter: go-getter vulnerable to denial of service via malicious compressed archive2023-02-16
Microsoft
Go-Getter Vulnerable to Decompression Bombs2023-02-14
Debian
CVE-2023-0475: golang-github-hashicorp-go-getter - HashiCorp go-getter up to 1.6.2 and 2.1.1 is vulnerable to decompression bombs. ...2023
CVE-2023-0475 — Hashicorp Go-getter vulnerability | cvebase