CVE-2022-30323

Publication date 25 May 2022

Last updated 24 June 2025


Ubuntu priority

Cvss 3 Severity Score

8.6 · High

Score breakdown

Description

go-getter up to 1.5.11 and 2.0.2 panicked when processing password-protected ZIP files. Fixed in 1.6.1 and 2.1.0.

Status

Package Ubuntu Release Status
golang-github-hashicorp-go-getter 25.04 plucky
Vulnerable
24.10 oracular Ignored end of life, was needed
24.04 LTS noble
Vulnerable
23.10 mantic Ignored end of life, was needs-triage
23.04 lunar Ignored end of life, was needs-triage
22.10 kinetic Ignored end of life, was needs-triage
22.04 LTS jammy
Vulnerable
21.10 impish Ignored end of life
20.04 LTS focal
Vulnerable
18.04 LTS bionic
Vulnerable
golang-github-jesseduffield-go-getter 25.04 plucky Not in release
24.10 oracular Ignored end of life, was needed
24.04 LTS noble
Vulnerable
23.10 mantic Ignored end of life, was needs-triage
22.04 LTS jammy
Vulnerable
20.04 LTS focal
Vulnerable

Severity score breakdown

Parameter Value
Base score 8.6 · High
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Scope Unchanged
Confidentiality Low
Integrity impact Low
Availability impact High
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H