HashiCorp go-slug 0.4.0 through 0.18.2 could allow a local attacker to bypass .terraformignore exclusions and cause sensitive files to be included in Terraform slug uploads due to improper handling of Unicode normalization during path matching.
oryginał ENCVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NHashicorp Go Slug
APPHashicorp0.4.0 – 0.18.3 (bez)
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje
Powiązane podatności
CVE-2025-0377HIGH7.5ten sam produkt
HashiCorp’s go-slug library is vulnerable to a zip-slip style attack when a non-existing user-provided path is...
CVE-2020-29529HIGH7.5ten sam produkt
HashiCorp go-slug up to 0.4.3 did not fully protect against directory traversal while unpacking tar archives, ...
CVE-2025-6000CRITICAL9.1PL ✓ten sam vendor
HashiCorp Vault: RCE przez uprzywilejowanego operatora via sys/audit
CVE-2024-3817CRITICAL9.8PL ✓ten sam vendor
HashiCorp go-getter: argument injection przy odkrywaniu zdalnych gałęzi Git
CVE-2023-1782CRITICAL9.9PL ✓ten sam vendor
HashiCorp Nomad: obejście ACL przez nieuwierzytelnionych użytkowników