Vulnerabilities > Hashicorp > GO Slug

DATE CVE VULNERABILITY TITLE RISK
2020-12-03 CVE-2020-29529 Link Following vulnerability in Hashicorp Go-Slug
HashiCorp go-slug up to 0.4.3 did not fully protect against directory traversal while unpacking tar archives, and protections could be bypassed with specific constructions of multiple symlinks.
network
low complexity
hashicorp CWE-59
7.5