The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade github.com/hashicorp/go-slug/internal/ignorefiles to version 0.18.3 or higher.
Affected versions of this package are vulnerable to Path Equivalence in its .terraformignore pattern matching, which compares filenames against ignore patterns without normalizing both to a common Unicode form. An attacker with write access to the working directory can cause sensitive files to be included in a Terraform slug upload despite an exclusion rule that should match them, by naming a file in a Unicode form that differs from the form used in the pattern. This requires local access to the working directory and a filename and pattern that differ only by Unicode normalization, which arises primarily on macOS filesystems.