go-getter up to 1.5.11 and 2.0.2 allowed protocol switching, endless redirect, and configuration bypass via abuse of custom HTTP response header processing. Fixed in 1.6.1 and 2.1.0.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| github.com/hashicorp/go-getter(Go) | 0 | 1.6.1 | N/A |
| github.com/hashicorp/go-getter(Go) | 2.0.0 | 2.1.0 | N/A |
| github.com/hashicorp/go-getter/v2(Go) | 0 | 2.1.0 | N/A |
| github.com/hashicorp/go-getter/s3/v2(Go) | 0 | 2.1.0 | N/A |
| github.com/hashicorp/go-getter/gcs/v2(Go) | 0 | 2.1.0 | N/A |
CVSS Metrics