CVE-2022-26945

HIGH8.6EPSS 0.20%

HashiCorp go-getter unsafe downloads

Published: 5/26/2022Modified: 3/15/2024

Description

HashiCorp go-getter through 2.0.2 does not safely perform downloads. Protocol switching, endless redirect, and configuration bypass were possible via abuse of custom HTTP response header processing.

Affected packages (21)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH8.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

References (15)