Логотип exploitDog
bind:CVE-2023-27475
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-27475

Количество 2

Количество 2

nvd логотип

CVE-2023-27475

почти 3 года назад

Goutil is a collection of miscellaneous functionality for the go language. In versions prior to 0.6.0 when users use fsutil.Unzip to unzip zip files from a malicious attacker, they may be vulnerable to path traversal. This vulnerability is known as a ZipSlip. This issue has been fixed in version 0.6.0, users are advised to upgrade. There are no known workarounds for this issue.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-fx2v-qfhr-4chv

почти 3 года назад

Goutil vulnerable to path traversal when unzipping files

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-27475

Goutil is a collection of miscellaneous functionality for the go language. In versions prior to 0.6.0 when users use fsutil.Unzip to unzip zip files from a malicious attacker, they may be vulnerable to path traversal. This vulnerability is known as a ZipSlip. This issue has been fixed in version 0.6.0, users are advised to upgrade. There are no known workarounds for this issue.

CVSS3: 8.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-fx2v-qfhr-4chv

Goutil vulnerable to path traversal when unzipping files

CVSS3: 8.8
0%
Низкий
почти 3 года назад

Уязвимостей на страницу