CVE-2025-0377

Aliases:GHSA-wpfp-cm49-9m9qGO-2025-3413CGA-67cr-8jw2-cp8xCGA-7vc6-6r4m-5mq5CGA-9q3r-f772-gx53CGA-gg49-gcc5-jx6hCGA-h99m-78f9-rpr2CGA-36m9-p6r2-r7ggCGA-4cv4-758c-c3mjCGA-5fh5-7hvw-2q9hCGA-5hmx-cr8q-mxfxCGA-6924-mvm2-c85qCGA-6q6x-j745-7jg4CGA-73ww-79f6-8jr2CGA-74w8-c8fc-xpwgCGA-78hw-7h2h-855rCGA-7cw8-3hv7-3v4cCGA-7qjq-5ch3-j6x3CGA-87w4-4pxc-482hCGA-88xp-55jf-77v7CGA-8mrw-7cm3-87q6CGA-9jjq-ffgc-2922CGA-c84v-fhh6-w227CGA-gg34-f695-8mq9CGA-h75c-584p-2426CGA-hfq4-vpf7-28g6CGA-hp8r-8frq-9gj5CGA-mx43-92rc-hq3vCGA-pmh2-jh27-j98rCGA-qp82-mrpj-33mqCGA-qq6g-5jhq-3jcrCGA-r74w-v358-ccx4CGA-r94h-35gc-27xqCGA-w59w-vf2f-c2rfCGA-w5qr-6p6v-3g92CGA-w8xj-x8v9-qf9vCGA-w943-p476-wh99CGA-wch5-2qxf-fr39CGA-x79f-qjx6-rf7cCGA-x946-8j96-5gqg
Analyzed
Published: 21 Jan 2025, 15:23
Last modified:12 Feb 2025, 20:41

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.1 CRITICAL
v3.1 (nvd)
EPSS Score
0.69% LOW
1% probability +0.58%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

21 Jan 2025, 15:23
Published
Vulnerability first disclosed
12 Feb 2025, 20:41
Last Modified
Vulnerability information updated

Description

HashiCorp’s go-slug library is vulnerable to a zip-slip style attack when a non-existing user-provided path is extracted from the tar entry.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • v3.1CRITICALScore: 9.1CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

EPSS Trends

Current EPSS score: 0.69% Percentile: 51%

Techniques & Countermeasures

  • CWE-59Improper Link Resolution Before File Access ('Link Following')

    The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Affected Systems

  • chainguardopentofu-1.8

    < 1.8.8-r2

  • chainguardopentofu-1.8-compat

    < 1.8.8-r2

  • chainguardopentofu-1.8-local-provider-config

    < 1.8.8-r2

  • chainguardopentofu-1.9

    < 1.9.0-r2

  • chainguardopentofu-fips-1.8

    < 1.8.8-r1

  • chainguardopentofu-fips-1.9

    < 1.9.0-r1

  • chainguardterraform

    < 1.5.7-r21

  • chainguardterraform-1.10

    < 1.10.4-r1

  • chainguardterraform-1.9

    < 1.9.8-r5

  • chainguardterraform-1.9-compat

    < 1.9.8-r5

  • chainguardterraform-1.9-local-provider-config

    < 1.9.8-r5

  • chainguardterraform-compat

    < 1.5.7-r36

  • chainguardterraform-local-provider-config

    < 1.5.7-r36

  • chainguardvault-1.16

    < 1.16.3-r9

  • chainguardvault-1.16-compat

    < 1.16.3-r9

  • chainguardvault-1.17

    < 1.17.6-r3

  • chainguardvault-1.17-compat

    < 1.17.6-r3

  • chainguardvault-1.18

    < 1.18.3-r2

  • chainguardvault-1.18-compat

    < 1.18.3-r2

  • wolfiopentofu-1.9

    < 1.9.0-r2

  • wolfiterraform

    < 1.5.7-r21

  • wolfiterraform-compat

    < 1.5.7-r36

  • wolfiterraform-local-provider-config

    < 1.5.7-r36

  • github.com/hashicorpgo-slug

    < 0.16.3

  • hashicorpgo-slug

    < 0.16.3

  • hashicorpshared library

    < 0.16.2

References (6)