Buffer Overflow in Go-Getter Library by HashiCorp
CVE-2022-30323
8.6HIGH
Summary
The Go-Getter library by HashiCorp experienced a significant issue when processing password-protected ZIP files, leading to potential buffer overflow scenarios. This vulnerability could cause the application to panic, thereby interrupting service and risking data integrity. The affected versions are up to 1.5.11 and 2.0.2, with fixes released in versions 1.6.1 and 2.1.0. Users are strongly encouraged to update to the latest version to mitigate the risk associated with this vulnerability.
References
CVSS V3.1
Score:
8.6
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved