MEDIUM🇬🇧 English

CVE-2026-14978

CVSS 5.5v3.1pub. 2026-08-19upd. 2026-09-04

HashiCorp go-slug 0.4.0 through 0.18.2 could allow a local attacker to bypass .terraformignore exclusions and cause sensitive files to be included in Terraform slug uploads due to improper handling of Unicode normalization during path matching.

oryginał EN
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
  • Hashicorp Go Slug

    APP
    Hashicorp
    0.4.0 – 0.18.3 (bez)
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2025-0377HIGH7.5ten sam produkt

HashiCorp’s go-slug library is vulnerable to a zip-slip style attack when a non-existing user-provided path is...

CVE-2020-29529HIGH7.5ten sam produkt

HashiCorp go-slug up to 0.4.3 did not fully protect against directory traversal while unpacking tar archives, ...

CVE-2025-6000CRITICAL9.1PL ✓ten sam vendor

HashiCorp Vault: RCE przez uprzywilejowanego operatora via sys/audit

CVE-2024-3817CRITICAL9.8PL ✓ten sam vendor

HashiCorp go-getter: argument injection przy odkrywaniu zdalnych gałęzi Git

CVE-2023-1782CRITICAL9.9PL ✓ten sam vendor

HashiCorp Nomad: obejście ACL przez nieuwierzytelnionych użytkowników