ZeroHour

CVE-2020-29529

PoC
CVSS 3.1
7.5 high
EPSS
3%p86
Published
()
Modified
Description

HashiCorp go-slug up to 0.4.3 did not fully protect against directory traversal while unpacking tar archives, and protections could be bypassed with specific constructions of multiple symlinks. Fixed in 0.5.0.

Vendors
hashicorp
Products
go-slug
Weakness
CWE-22, CWE-59
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.