HashiCorp go-slug up to 0.4.3 did not fully protect against directory traversal while unpacking tar archives, and protections could be bypassed with specific constructions of multiple symlinks. Fixed in 0.5.0.
Metrics
Affected Vendors & Products
References
History
Sun, 08 Sep 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Redhat
Redhat acm |
|
CPEs | cpe:/a:redhat:acm:2.2::el7 | |
Vendors & Products |
Redhat
Redhat acm |
Mon, 19 Aug 2024 22:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:/a:redhat:acm:2.2::el8 |
|
Vendors & Products |
Redhat
Redhat acm |

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T16:55:10.521Z
Reserved: 2020-12-03T00:00:00
Link: CVE-2020-29529

No data.

Status : Modified
Published: 2020-12-03T20:15:11.820
Modified: 2024-11-21T05:24:09.323
Link: CVE-2020-29529
