CVE-2020-29529
EUVD-2023-060003.12.2020, 20:15
HashiCorp go-slug up to 0.4.3 did not fully protect against directory traversal while unpacking tar archives, and protections could be bypassed with specific constructions of multiple symlinks. Fixed in 0.5.0.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| hashicorp | go-slug | 𝑥 < 0.5.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
References