Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-2g5j-5x95-r6hr: Unsafe tar unpacking in HashiCorp go-slug

HashiCorp go-slug before 0.5.0 does not address attempts at directory traversal involving …/ and symlinks.

ghsa
#git

Unsafe tar unpacking in HashiCorp go-slug

High severity GitHub Reviewed Published Feb 6, 2023 to the GitHub Advisory Database • Updated Feb 6, 2023

ghsa: Latest News

GHSA-hhw4-xg65-fp2x: serde_yml crate is unsound and unmaintained