Unsafe tar unpacking in HashiCorp go-slug
High severity
GitHub Reviewed
Published
Feb 6, 2023
to the GitHub Advisory Database
•
Updated Feb 6, 2023
Description
Published to the GitHub Advisory Database
Feb 6, 2023
Reviewed
Feb 6, 2023
Last updated
Feb 6, 2023
HashiCorp go-slug before 0.5.0 does not address attempts at directory traversal involving ../ and symlinks.
References