Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jcxc-rh6w-wf49

Опубликовано: 06 янв. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Link Following in Iris

This affects all versions of package github.com/kataras/iris; all versions of package github.com/kataras/iris/v12. The unsafe handling of file names during upload using UploadFormFiles method may enable attackers to write to arbitrary locations outside the designated target folder.

Пакеты

Наименование

github.com/kataras/iris/v12

go
Затронутые версииВерсия исправления

< 12.2.0-alpha8

12.2.0-alpha8

Наименование

github.com/kataras/iris

go
Затронутые версииВерсия исправления

<= 0.0.2

Отсутствует

EPSS

Процентиль: 71%
0.00662
Низкий

7.5 High

CVSS3

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 8.8
redhat
около 4 лет назад

This affects all versions of package github.com/kataras/iris; all versions of package github.com/kataras/iris/v12. The unsafe handling of file names during upload using UploadFormFiles method may enable attackers to write to arbitrary locations outside the designated target folder.

CVSS3: 7.5
nvd
около 4 лет назад

This affects all versions of package github.com/kataras/iris; all versions of package github.com/kataras/iris/v12. The unsafe handling of file names during upload using UploadFormFiles method may enable attackers to write to arbitrary locations outside the designated target folder.

EPSS

Процентиль: 71%
0.00662
Низкий

7.5 High

CVSS3

Дефекты

CWE-59