HashiCorp go-getter unsafe downloads could lead to asymmetric resource exhaustion
High severity
GitHub Reviewed
Published
May 26, 2022
to the GitHub Advisory Database
•
Updated May 20, 2024
Description
Published by the National Vulnerability Database
May 25, 2022
Published to the GitHub Advisory Database
May 26, 2022
Reviewed
Jun 1, 2022
Last updated
May 20, 2024
HashiCorp go-getter through 2.0.2 does not safely perform downloads. Asymmetric resource exhaustion could occur when go-getter processed malicious HTTP responses.
References