CVE-2022-26945

go-getter up to 1.5.11 and 2.0.2 allowed protocol switching, endless redirect, and configuration bypass via abuse of custom HTTP response header processing. Fixed in 1.6.1 and 2.1.0.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hashicorp:go-getter:*:*:*:*:*:*:*:*
cpe:2.3:a:hashicorp:go-getter:2.0.2:*:*:*:*:*:*:*

History

08 Aug 2023, 14:21

Type Values Removed Values Added
CWE CWE-77 NVD-CWE-noinfo

10 Aug 2022, 22:15

Type Values Removed Values Added
Summary HashiCorp go-getter before 2.0.2 allows Command Injection. go-getter up to 1.5.11 and 2.0.2 allowed protocol switching, endless redirect, and configuration bypass via abuse of custom HTTP response header processing. Fixed in 1.6.1 and 2.1.0.

31 May 2022, 23:17

Type Values Removed Values Added
References (MISC) https://discuss.hashicorp.com - (MISC) https://discuss.hashicorp.com - Vendor Advisory
References (MISC) https://discuss.hashicorp.com/t/hcsec-2022-13-multiple-vulnerabilities-in-go-getter-library/39930 - (MISC) https://discuss.hashicorp.com/t/hcsec-2022-13-multiple-vulnerabilities-in-go-getter-library/39930 - Mitigation, Vendor Advisory
CPE cpe:2.3:a:hashicorp:go-getter:*:*:*:*:*:*:*:*
cpe:2.3:a:hashicorp:go-getter:2.0.2:*:*:*:*:*:*:*
CWE CWE-77
First Time Hashicorp go-getter
Hashicorp
CVSS v2 : unknown
v3 : unknown
v2 : 7.5
v3 : 9.8

25 May 2022, 13:57

Type Values Removed Values Added
New CVE

Information

Published : 2022-05-25 12:15

Updated : 2023-12-10 14:22


NVD link : CVE-2022-26945

Mitre link : CVE-2022-26945

CVE.ORG link : CVE-2022-26945


JSON object : View

Products Affected

hashicorp

  • go-getter