Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
HashiCorp go-slug up to 0.4.3 did not fully protect against directory traversal while unpacking tar archives, and protections could be bypassed with specific constructions of multiple symlinks. Fixed in 0.5.0.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Hashicorp Go-slug 路径遍历漏洞
Vulnerability Description
Hashicorp Go-slug是美国Hashicorp公司的一个基于Go的用于打包解压文件的代码库。 HashiCorp go-slug 0.5.0之前版本存在路径遍历漏洞,该漏洞源于不会处理涉及../的目录遍历尝试和符号链接。
CVSS Information
N/A
Vulnerability Type
N/A