QID 981874
QID 981874: Go (go) Security Update for github.com/unknwon/cae/tz (GHSA-88jf-7rch-32qc)
"The ExtractTo function doesn't securely escape file paths in zip archives which include leading or non-leading "..". This allows an attacker to add or replace files system-wide."
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-88jf-7rch-32qc for updates pertaining to this vulnerability.
Vendor References
- GHSA-88jf-7rch-32qc -
github.com/advisories/GHSA-88jf-7rch-32qc
CVEs related to QID 981874
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-88jf-7rch-32qc | github.com/unknwon/cae/tz |
|