HashiCorp go-getter is vulnerable to decompression bombs. This can lead to excessive memory consumption and denial-of-service attacks.
{
"review_status": "REVIEWED",
"url": "https://pkg.go.dev/vuln/GO-2023-1578"
}{
"imports": [
{
"symbols": [
"Bzip2Decompressor.Decompress",
"Client.Get",
"Client.GetChecksum",
"FolderStorage.Get",
"Get",
"GetAny",
"GetFile",
"GzipDecompressor.Decompress",
"HttpGetter.Get",
"Request.CopyReader",
"TarBzip2Decompressor.Decompress",
"TarGzipDecompressor.Decompress",
"TarXzDecompressor.Decompress",
"XzDecompressor.Decompress",
"ZipDecompressor.Decompress",
"copyReader",
"untar"
],
"path": "github.com/hashicorp/go-getter/v2"
}
]
}
{
"imports": [
{
"symbols": [
"Bzip2Decompressor.Decompress",
"Client.ChecksumFromFile",
"Client.Get",
"FolderStorage.Get",
"GCSGetter.Get",
"GCSGetter.GetFile",
"Get",
"GetAny",
"GetFile",
"GzipDecompressor.Decompress",
"HttpGetter.Get",
"S3Getter.Get",
"S3Getter.GetFile",
"TarBzip2Decompressor.Decompress",
"TarDecompressor.Decompress",
"TarGzipDecompressor.Decompress",
"TarXzDecompressor.Decompress",
"TarZstdDecompressor.Decompress",
"XzDecompressor.Decompress",
"ZipDecompressor.Decompress",
"ZstdDecompressor.Decompress",
"copyReader",
"untar"
],
"path": "github.com/hashicorp/go-getter"
}
]
}