Known vulnerabilities in go-slug
Vendor:
HashiCorp
Software:
go-slug
Software CPE:
cpe:2.3:a:hashicorp:go-slug:*:*:*:*:*:*:*:*
Website:
https://www.hashicorp.com/
Total vulnerabilities:
2
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
1.0.0
0.18.2
0.18.1
0.18.0
0.17.1
0.17.0
0.16.8
0.16.7
0.16.6
0.16.5
0.16.4
0.16.3
0.16.2
0.16.1
0.16.0
0.15.2
0.15.1
0.15.0
0.14.0
0.13.4
0.13.3
0.13.2
0.13.1
0.13.0
0.12.2
0.12.1
0.12.0
0.11.1
0.11.0
0.10.1
0.10.0
0.9.1
0.9.0
0.8.1
0.8.0
0.7.0
0.6.0
0.5.0
0.4.3
0.4.2
0.4.1
0.4.0
0.3.1
0.3.0
0.2.0
0.1.0
Vulnerabilities (2)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU111999 - Improper Link Resolution Before File Access ('Link Following') CVE-2025-0377 |
CWE-59 | High | 0.16.3 | 27.06.2025 |
SB2025062727 SB2025062728 SB2025063009 and 1 more |
||
| #VU48809 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2020-29529 |
CWE-22 | Medium | 0.5.0 | 03.12.2020 |
SB2020120722 SB2022112521 SB2021041399 |