CVE-2020-29529

HIGH

HashiCorp go-slug <0.5.0 - Path Traversal

Title source: llm
STIX 2.1

Description

HashiCorp go-slug up to 0.4.3 did not fully protect against directory traversal while unpacking tar archives, and protections could be bypassed with specific constructions of multiple symlinks. Fixed in 0.5.0.

References (4)

Core 4
Core References
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/hashicorp/go-slug/releases/tag/v0.5.0
Patch, Release Notes, Third Party Advisory x_refsource_misc
https://github.com/hashicorp/go-slug/compare/v0.4.3...v0.5.0
Patch, Third Party Advisory x_refsource_misc
https://github.com/hashicorp/go-slug/pull/12
Exploit, Third Party Advisory x_refsource_misc
https://securitylab.github.com/advisories/GHSL-2020-262-zipslip-go-slug

Scores

CVSS v3 7.5
EPSS 0.0044
EPSS Percentile 63.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-22 CWE-59
Status published
Products (2)
hashicorp/go-slug < 0.5.0
hashicorp/go-slug 0 - 0.5.0Go
Published Dec 03, 2020
Tracked Since Feb 18, 2026