hashicorp/go-slug

hashicorp/go-slug

Releases46
Frequency2 months 2 hours
Last Release
Stars27
The slug package provides functions to create slug archives

CVE History

CVEPublishedCVSS v3CVSS v2
7.5 HIGH5 MEDIUM

HashiCorp go-slug up to 0.4.3 did not fully protect against directory traversal while unpacking tar archives, and protections could be bypassed with specific constructions of multiple symlinks. Fixed in 0.5.0.