PT-2023-16290 · Hashicorp+1 · Go-Getter+1

Published

2023-02-16

·

Updated

2023-02-27

·

CVE-2023-0475

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions HashiCorp go-getter versions 1.6.2 and earlier, 2.1.1 and earlier
Description The issue concerns decompression bombs, which can lead to excessive memory consumption and denial-of-service attacks.
Recommendations For versions 1.6.2 and earlier, update to version 1.7.0 or later. For version 2.1.1, update to version 2.2.0 or later.

Fix

Weakness Enumeration

Related Identifiers

AZL-13586
AZL-13606
CVE-2023-0475
GHSA-JPXJ-2JVG-6JV9
GO-2023-1578

Affected Products

Debian
Go-Getter