CVE-2025-0377
21.01.2025, 16:15
HashiCorps go-slug library is vulnerable to a zip-slip style attack when a non-existing user-provided path is extracted from the tar entry.
| Vendor | Product | Version |
|---|---|---|
| hashicorp | go-slug | 𝑥 < 0.16.3 |
𝑥
= Vulnerable software versions