Описание
Goutil is a collection of miscellaneous functionality for the go language. In versions prior to 0.6.0 when users use fsutil.Unzip to unzip zip files from a malicious attacker, they may be vulnerable to path traversal. This vulnerability is known as a ZipSlip. This issue has been fixed in version 0.6.0, users are advised to upgrade. There are no known workarounds for this issue.
Ссылки
- Patch
- Vendor Advisory
- Patch
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.6.0 (исключая)
cpe:2.3:a:goutil_project:goutil:*:*:*:*:*:go:*:*
EPSS
Процентиль: 55%
0.00328
Низкий
8.8 High
CVSS3
Дефекты
CWE-22
Связанные уязвимости
CVSS3: 8.8
github
почти 3 года назад
Goutil vulnerable to path traversal when unzipping files
EPSS
Процентиль: 55%
0.00328
Низкий
8.8 High
CVSS3
Дефекты
CWE-22