HashiCorp go-getter up to 1.6.2 and 2.1.1 is vulnerable to decompression bombs. Fixed in 1.7.0 and 2.2.0.
{
"nvd_published_at": "2023-02-16T19:15:00Z",
"github_reviewed_at": "2023-02-16T23:34:17Z",
"github_reviewed": true,
"cwe_ids": [
"CWE-409"
],
"severity": "MODERATE"
}