CVE-2022-30321
25.05.2022, 12:15
go-getter up to 1.5.11 and 2.0.2 allowed arbitrary host access via go-getter path traversal, symlink processing, and command injection flaws. Fixed in 1.6.1 and 2.1.0.
| Vendor | Product | Version |
|---|---|---|
| hashicorp | go-getter | 𝑥 ≤ 1.5.11 |
| hashicorp | go-getter | 2.0.2 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
References