CVE-2025-0377 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

HashiCorp’s go-slug library is vulnerable to a zip-slip style attack when a non-existing user-provided path is extracted from the tar entry.
High CVSS: 7.5

CVE-2025-0377

HashiCorp’s go-slug library is vulnerable to a zip-slip style attack when a non-existing user-provided path is extracted from the tar entry.
Vendor
Hashicorp
Product
Go-slug
CWE
CWE-59
Yayın Tarihi
2025-01-21 16:15:14
Güncelleme
2025-12-15 21:00:36
Source Identifier
security@hashicorp.com
KEV Date Added
-

Kategoriler

Referanslar