Resource Exhaustion Vulnerability in go-getter by HashiCorp
CVE-2022-30322
8.6HIGH
Summary
The go-getter library prior to version 1.6.1 and 2.1.0 is susceptible to a vulnerability where it can become overwhelmed by asymmetric resource exhaustion due to the processing of malicious HTTP responses. This flaw can potentially disrupt the normal operation of applications utilizing the go-getter library, leading to performance degradation or system instability. Users are advised to update to the latest versions to mitigate this risk.
References
CVSS V3.1
Score:
8.6
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved