ZeroHour

CVE-2022-26945

CVSS 3.1
9.8 critical
EPSS
2%p76
Published
()
Modified
Description

go-getter up to 1.5.11 and 2.0.2 allowed protocol switching, endless redirect, and configuration bypass via abuse of custom HTTP response header processing. Fixed in 1.6.1 and 2.1.0.

Vendors
hashicorp
Products
go-getter
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.