QID 981873
QID 981873: Go (go) Security Update for github.com/unknwon/cae/zip (GHSA-vpx7-vm66-qx8r)
The ExtractTo function doesn't securely escape file paths in zip archives which include leading or non-leading "..". This allows an attacker to add or replace files system-wide.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-vpx7-vm66-qx8r for updates pertaining to this vulnerability.
Vendor References
- GHSA-vpx7-vm66-qx8r -
github.com/advisories/GHSA-vpx7-vm66-qx8r
CVEs related to QID 981873
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-vpx7-vm66-qx8r | github.com/unknwon/cae/zip |
|