Vulnerability Description
HashiCorp’s go-getter library is vulnerable to argument injection when executing Git to discover remote branches. This vulnerability does not affect the go-getter/v2 branch and package.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hashicorp | Go-Getter | >= 1.5.9, < 1.7.4 |
Related Weaknesses (CWE)
References
- https://discuss.hashicorp.com/t/hcsec-2024-09-hashicorp-go-getter-vulnerable-to-Vendor Advisory
- https://discuss.hashicorp.com/t/hcsec-2024-09-hashicorp-go-getter-vulnerable-to-Vendor Advisory
FAQ
What is CVE-2024-3817?
CVE-2024-3817 is a vulnerability with a CVSS score of 9.8 (CRITICAL). HashiCorp’s go-getter library is vulnerable to argument injection when executing Git to discover remote branches. This vulnerability does not affect the go-getter/v2 branch and package.
How severe is CVE-2024-3817?
CVE-2024-3817 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-3817?
Check the references section above for vendor advisories and patch information. Affected products include: Hashicorp Go-Getter.