CVE-2024-3817

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/04/2024
Last modified:
11/12/2025

Description

HashiCorp’s go-getter library is vulnerable to argument injection when executing Git to discover remote branches. <br /> <br /> This vulnerability does not affect the go-getter/v2 branch and package.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hashicorp:go-getter:*:*:*:*:*:*:*:* 1.5.9 (including) 1.7.4 (excluding)