CVE-2025-0377
Aliases:GHSA-wpfp-cm49-9m9qGO-2025-3413CGA-67cr-8jw2-cp8xCGA-7vc6-6r4m-5mq5CGA-9q3r-f772-gx53CGA-gg49-gcc5-jx6hCGA-h99m-78f9-rpr2CGA-36m9-p6r2-r7ggCGA-4cv4-758c-c3mjCGA-5fh5-7hvw-2q9hCGA-5hmx-cr8q-mxfxCGA-6924-mvm2-c85qCGA-6q6x-j745-7jg4CGA-73ww-79f6-8jr2CGA-74w8-c8fc-xpwgCGA-78hw-7h2h-855rCGA-7cw8-3hv7-3v4cCGA-7qjq-5ch3-j6x3CGA-87w4-4pxc-482hCGA-88xp-55jf-77v7CGA-8mrw-7cm3-87q6CGA-9jjq-ffgc-2922CGA-c84v-fhh6-w227CGA-gg34-f695-8mq9CGA-h75c-584p-2426CGA-hfq4-vpf7-28g6CGA-hp8r-8frq-9gj5CGA-mx43-92rc-hq3vCGA-pmh2-jh27-j98rCGA-qp82-mrpj-33mqCGA-qq6g-5jhq-3jcrCGA-r74w-v358-ccx4CGA-r94h-35gc-27xqCGA-w59w-vf2f-c2rfCGA-w5qr-6p6v-3g92CGA-w8xj-x8v9-qf9vCGA-w943-p476-wh99CGA-wch5-2qxf-fr39CGA-x79f-qjx6-rf7cCGA-x946-8j96-5gqg
Advisory lineage Upstream: 0 Downstream: 4
Analyzed
Published: 21 Jan 2025, 15:23
Last modified:12 Feb 2025, 20:41
Vulnerability Summary
Overall Risk (default)
high
70/100 CVSS Score
9.1 CRITICAL
v3.1 (nvd)
EPSS Score
0.69% LOW
1% probability +0.58%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
21 Jan 2025, 15:23
Published
Vulnerability first disclosed
12 Feb 2025, 20:41
Last Modified
Vulnerability information updated
Description
HashiCorp’s go-slug library is vulnerable to a zip-slip style attack when a non-existing user-provided path is extracted from the tar entry.
CVSS Metrics
- v3.1•HIGH•Score: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- v3.1•CRITICAL•Score: 9.1CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Trends
Current EPSS score: 0.69%• Percentile: 51%
Techniques & Countermeasures
- CWE-59•Improper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Affected Systems
- chainguard•opentofu-1.8
< 1.8.8-r2
- chainguard•opentofu-1.8-compat
< 1.8.8-r2
- chainguard•opentofu-1.8-local-provider-config
< 1.8.8-r2
- chainguard•opentofu-1.9
< 1.9.0-r2
- chainguard•opentofu-fips-1.8
< 1.8.8-r1
- chainguard•opentofu-fips-1.9
< 1.9.0-r1
- chainguard•terraform
< 1.5.7-r21
- chainguard•terraform-1.10
< 1.10.4-r1
- chainguard•terraform-1.9
< 1.9.8-r5
- chainguard•terraform-1.9-compat
< 1.9.8-r5
- chainguard•terraform-1.9-local-provider-config
< 1.9.8-r5
- chainguard•terraform-compat
< 1.5.7-r36
- chainguard•terraform-local-provider-config
< 1.5.7-r36
- chainguard•vault-1.16
< 1.16.3-r9
- chainguard•vault-1.16-compat
< 1.16.3-r9
- chainguard•vault-1.17
< 1.17.6-r3
- chainguard•vault-1.17-compat
< 1.17.6-r3
- chainguard•vault-1.18
< 1.18.3-r2
- chainguard•vault-1.18-compat
< 1.18.3-r2
- wolfi•opentofu-1.9
< 1.9.0-r2
- wolfi•terraform
< 1.5.7-r21
- wolfi•terraform-compat
< 1.5.7-r36
- wolfi•terraform-local-provider-config
< 1.5.7-r36
- github.com/hashicorp•go-slug
< 0.16.3
- hashicorp•go-slug
< 0.16.3
- hashicorp•shared library
< 0.16.2
References (6)
- https://discuss.hashicorp.com/t/hcsec-2025-01-hashicorp-go-slug-vulnerable-to-zip-slip-attack
- https://nvd.nist.gov/vuln/detail/CVE-2025-0377
- github.com/hashicorp/go-slug
- https://github.com/advisories/GHSA-wpfp-cm49-9m9q
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/0xxx/CVE-2025-0377.json
- https://github.com/hashicorp/go-slug