Description
HashiCorp’s go-getter library is vulnerable to argument injection when executing Git to discover remote branches.
This vulnerability does not affect the go-getter/v2 branch and package.
This vulnerability does not affect the go-getter/v2 branch and package.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1274 | HashiCorp’s go-getter library is vulnerable to argument injection when executing Git to discover remote branches. This vulnerability does not affect the go-getter/v2 branch and package. |
Github GHSA |
GHSA-q64h-39hv-4cf7 | HashiCorp go-getter Vulnerable to Argument Injection When Fetching Remote Default Git Branches |
References
History
Thu, 11 Dec 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:hashicorp:go-getter:*:*:*:*:*:*:*:* |
Status: PUBLISHED
Assigner: HashiCorp
Published:
Updated: 2024-08-01T20:20:01.607Z
Reserved: 2024-04-15T14:04:27.869Z
Link: CVE-2024-3817
Updated: 2024-08-01T20:20:01.607Z
Status : Analyzed
Published: 2024-04-17T20:15:08.383
Modified: 2025-12-11T20:03:00.883
Link: CVE-2024-3817
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:45:17Z
Weaknesses
EUVD
Github GHSA