QID 994859
Date Published: 2023-08-17
QID 994859: GO (Go) Security Update for github.com/yaklang/yaklang (GHSA-xvhg-w6qc-m3qq)
The Yak Engine has been found to contain a local file inclusion (LFI) vulnerability. This vulnerability allows attackers to include files from the server's local file system through the web application. When exploited, this can lead to the unintended exposure of sensitive data, potential remote code execution, or other security breaches. Users utilizing versions of the Yak Engine prior to 1.2.4-sp1 are impacted.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-xvhg-w6qc-m3qq for updates and patch information.
Vendor References
- GHSA-xvhg-w6qc-m3qq -
github.com/advisories/GHSA-xvhg-w6qc-m3qq
CVEs related to QID 994859
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-xvhg-w6qc-m3qq | github.com/yaklang/yaklang |
|