github.com/hashicorp/go-getter/v2
Package for downloading things from a string URL using a variety of protocols.
Activity
- Latest release
- 3d ago
- Total releases
- 10
- Cadence
- ~3 months
- Last 12 months
- 1
Reach
- Stars
- 1.8k
Details
- First release
- Jan 04, 2021
| Version | Released | |
|---|---|---|
v2.2.4
patch
|
v2.2.4
patch
Dependencies (11)
+ 3 more |
|
v2.2.3
patch
|
v2.2.3
patch
Dependencies (10)
+ 2 more |
|
v2.2.2
patch
|
v2.2.2
patch
Dependencies (10)
+ 2 more |
|
v2.2.1
patch
|
v2.2.1
patch
Dependencies (10)
+ 2 more |
|
v2.2.0
minor
|
v2.2.0
minor
Dependencies (10)
+ 2 more |
|
v2.1.1
patch
1 CVE
CVE-2023-0475
GO-2023-1578
GHSA-jpxj-2jvg-6jv9
Feb 17, 2023
Denial of service in github.com/hashicorp/go-getter/v2 HashiCorp go-getter is vulnerable to decompression bombs. This can lead to excessive memory consumption and denial-of-service attacks. Fixed in
2.2.0
References Updated May 20, 2024 · Source: OSV.dev |
v2.1.1
patch
Dependencies (9)
+ 1 more |
|
v2.1.0
minor
1 CVE
CVE-2023-0475
GO-2023-1578
GHSA-jpxj-2jvg-6jv9
Feb 17, 2023
Denial of service in github.com/hashicorp/go-getter/v2 HashiCorp go-getter is vulnerable to decompression bombs. This can lead to excessive memory consumption and denial-of-service attacks. Fixed in
2.2.0
References Updated May 20, 2024 · Source: OSV.dev |
v2.1.0
minor
Dependencies (9)
+ 1 more |
|
v2.0.2
patch
2 CVEs
CVE-2023-0475
GO-2023-1578
GHSA-jpxj-2jvg-6jv9
Feb 17, 2023
Denial of service in github.com/hashicorp/go-getter/v2 HashiCorp go-getter is vulnerable to decompression bombs. This can lead to excessive memory consumption and denial-of-service attacks. Fixed in
2.2.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2022-26945
GHSA-x24g-9w7v-vprh
CVE-2022-30321
CVE-2022-30322
CVE-2022-30323
GHSA-28r2-q6m8-9hpx
GHSA-cjr4-fv6c-f3mv
GHSA-fcgg-rvwg-jv58
GO-2022-0586
May 26, 2022
HashiCorp go-getter command injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
HashiCorp go-getter before 2.0.2 allows Command Injection. Fixed in
2.1.0
References
Updated Mar 15, 2024 · Source: OSV.dev |
v2.0.2
patch
Dependencies (9)
+ 1 more |
|
v2.0.1
patch
2 CVEs
CVE-2023-0475
GO-2023-1578
GHSA-jpxj-2jvg-6jv9
Feb 17, 2023
Denial of service in github.com/hashicorp/go-getter/v2 HashiCorp go-getter is vulnerable to decompression bombs. This can lead to excessive memory consumption and denial-of-service attacks. Fixed in
2.2.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2022-26945
GHSA-x24g-9w7v-vprh
CVE-2022-30321
CVE-2022-30322
CVE-2022-30323
GHSA-28r2-q6m8-9hpx
GHSA-cjr4-fv6c-f3mv
GHSA-fcgg-rvwg-jv58
GO-2022-0586
May 26, 2022
HashiCorp go-getter command injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
HashiCorp go-getter before 2.0.2 allows Command Injection. Fixed in
2.1.0
References
Updated Mar 15, 2024 · Source: OSV.dev |
v2.0.1
patch
Dependencies (9)
+ 1 more |
|
v2.0.0
initial
2 CVEs
CVE-2023-0475
GO-2023-1578
GHSA-jpxj-2jvg-6jv9
Feb 17, 2023
Denial of service in github.com/hashicorp/go-getter/v2 HashiCorp go-getter is vulnerable to decompression bombs. This can lead to excessive memory consumption and denial-of-service attacks. Fixed in
2.2.0
References Updated May 20, 2024 · Source: OSV.dev
CVE-2022-26945
GHSA-x24g-9w7v-vprh
CVE-2022-30321
CVE-2022-30322
CVE-2022-30323
GHSA-28r2-q6m8-9hpx
GHSA-cjr4-fv6c-f3mv
GHSA-fcgg-rvwg-jv58
GO-2022-0586
May 26, 2022
HashiCorp go-getter command injection
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
HashiCorp go-getter before 2.0.2 allows Command Injection. Fixed in
2.1.0
References
Updated Mar 15, 2024 · Source: OSV.dev |
v2.0.0
initial
Dependencies (9)
+ 1 more |