This site requires JavaScript to be enabled to function correctly, please enable it.
Summary:
CVE-2024-6257 hashicorp/go-getter: Arbitrary command execution through local git config file
Product:
[Other] Security Response
Reporter:
Pedro Sampaio <psampaio>
Component:
vulnerability Assignee:
Product Security <prodsec-ir-bot>
Status:
NEW
---
QA Contact:
Severity:
medium
Docs Contact:
Priority:
medium
Version:
unspecified CC:
brainfor, dfreiber, drow, jburrell, lsharar, luizcosta, nweather, vkumar, zkayyali
Target Milestone:
--- Keywords:
Security
Target Release:
---
Hardware:
All
OS:
Linux
Whiteboard:
Fixed In Version:
go-getter 1.7.5
Doc Type:
If docs needed, set a value
Doc Text:
Story Points:
---
Clone Of:
Environment:
Last Closed:
Type:
---
Regression:
---
Mount Type:
---
Documentation:
---
CRM:
Verified Versions:
Category:
---
oVirt Team:
---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team:
---
Target Upstream Version:
Embargoed:
Bug Depends On:
2294255 , 2294256 , 2294257
Bug Blocks:
2294258