5
CVSSv2

CVE-2020-29529

Published: 03/12/2020 Updated: 08/03/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

HashiCorp go-slug up to 0.4.3 did not fully protect against directory traversal while unpacking tar archives, and protections could be bypassed with specific constructions of multiple symlinks. Fixed in 0.5.0.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

hashicorp go-slug

Vendor Advisories

Debian Bug report logs - #976873 golang-github-hashicorp-go-slug: CVE-2020-29529 Package: src:golang-github-hashicorp-go-slug; Maintainer for src:golang-github-hashicorp-go-slug is Debian Go Packaging Team <team+pkg-go@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 8 Dec 2020 20 ...