go-getter up to 1.5.11 and 2.0.2 allowed asymmetric resource exhaustion when go-getter processed malicious HTTP responses. Fixed in 1.6.1 and 2.1.0.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| github.com/hashicorp/go-getter(Go) | 0 | 1.6.1 | N/A |
| github.com/hashicorp/go-getter(Go) | 2.0.0 | 2.1.0 | N/A |
| github.com/hashicorp/go-getter/v2(Go) | 0 | 2.1.0 | N/A |
| github.com/hashicorp/go-getter/s3/v2(Go) | 0 | 2.1.0 | N/A |
| github.com/hashicorp/go-getter/gcs/v2(Go) | 0 | 2.1.0 | N/A |
CVSS Metrics