CVE-2024-6257: HashiCorp go-getter Vulnerable to Code Execution On Git Update Via Git Config Manipulation
HashiCorp’s go-getter library can be coerced into executing Git update on an existing maliciously modified Git Configuration, potentially leading to arbitrary code execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/github.com/hashicorp/go-getterto a version that resolves this vulnerability.Fixed in 1.7.5
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6257?
CVE-2024-6257 is considered a high severity vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2024-6257?
To fix CVE-2024-6257, upgrade the go-getter library to version 1.7.5 or later.
What software is affected by CVE-2024-6257?
CVE-2024-6257 affects the go-getter library from HashiCorp, specifically versions prior to 1.7.5.
What type of vulnerability is CVE-2024-6257?
CVE-2024-6257 is a code execution vulnerability that can be exploited via Git configuration manipulation.
Can CVE-2024-6257 be exploited remotely?
Yes, CVE-2024-6257 can potentially be exploited remotely if an attacker can manipulate the Git configuration.