Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-7668

Опубликовано: 23 июн. 2020
Источник: debian
EPSS Низкий

Описание

In all versions of the package github.com/unknwon/cae/tz, the ExtractTo function doesn't securely escape file paths in zip archives which include leading or non-leading "..". This allows an attacker to add or replace files system-wide.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-github-unknwon-caeremovedpackage

Примечания

  • https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMUNKNWONCAETZ-570384

EPSS

Процентиль: 57%
0.00346
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 5 лет назад

In all versions of the package github.com/unknwon/cae/tz, the ExtractTo function doesn't securely escape file paths in zip archives which include leading or non-leading "..". This allows an attacker to add or replace files system-wide.

CVSS3: 7.5
nvd
больше 5 лет назад

In all versions of the package github.com/unknwon/cae/tz, the ExtractTo function doesn't securely escape file paths in zip archives which include leading or non-leading "..". This allows an attacker to add or replace files system-wide.

CVSS3: 7.5
github
больше 4 лет назад

github.com/unknwon/cae Path Traversal vulnerability

EPSS

Процентиль: 57%
0.00346
Низкий