Goutil is a collection of miscellaneous functionality for the go language. In versions prior to 0.6.0 when users use fsutil.Unzip to unzip zip files from a malicious attacker, they may be vulnerable to path traversal. This vulnerability is known as a ZipSlip. This issue has been fixed in version 0.6.0, users are advised to upgrade. There are no known workarounds for this issue.
References
Configurations
History
21 Nov 2024, 07:52
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/gookit/goutil/commit/d7b94fede71f018f129f7d21feb58c895d28dadc - Patch | |
References | () https://github.com/gookit/goutil/security/advisories/GHSA-fx2v-qfhr-4chv - Vendor Advisory | |
References | () https://security.netapp.com/advisory/ntap-20230427-0003/ - |
Information
Published : 2023-03-07 18:15
Updated : 2024-11-21 07:52
NVD link : CVE-2023-27475
Mitre link : CVE-2023-27475
CVE.ORG link : CVE-2023-27475
JSON object : View
Products Affected
goutil_project
- goutil
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')