Bug 2275807 (CVE-2024-3817)

Summary: CVE-2024-3817 hashicorp/go-getter: argument injection when fetching remote default git branches
Product: [Other] Security Response Reporter: Robb Gatica <rgatica>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: CLOSED NOTABUG QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: vondruch
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: go-getter 1.7.4 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2024-04-19 09:36:25 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2275809, 2275808    
Bug Blocks:    

Description Robb Gatica 2024-04-17 21:34:14 UTC
Summary:
HashiCorp’s go-getter library is vulnerable to argument injection when executing Git to discover remote branches. This vulnerability does not affect the go-getter/v2 branch and package.

Affected Products / Versions: 
go-getter 1.5.9 up to 1.7.3; fixed in 1.7.4



https://discuss.hashicorp.com/t/hcsec-2024-09-hashicorp-go-getter-vulnerable-to-argument-injection-when-fetching-remote-default-git-branches/66040

Comment 1 Robb Gatica 2024-04-17 21:34:33 UTC
Created opentofu tracking bugs for this issue:

Affects: fedora-all [bug 2275808]


Created vagrant tracking bugs for this issue:

Affects: fedora-all [bug 2275809]

Comment 2 Vít Ondruch 2024-04-19 09:36:25 UTC
We are not using any Go functionality in Vagrant package.