Vulnerability Report: GO-2021-0228
- CVE-2020-7664, GHSA-vpx7-vm66-qx8r
- Affects: github.com/unknwon/cae
- Published: Jan 14, 2022
- Modified: May 20, 2024
The ExtractTo function doesn't securely escape file paths in zip archives which include leading or non-leading "..". This allows an attacker to add or replace files system-wide.
Affected Packages
-
PathGo VersionsSymbols
-
before v1.0.1
-
before v1.0.1
Aliases
References
- https://github.com/unknwon/cae/commit/07971c00a1bfd9dc171c3ad0bfab5b67c2287e11
- https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMUNKNWONCAEZIP-570383
- https://vuln.go.dev/ID/GO-2021-0228.json
Credits
- Georgios Gkitsas of Snyk Security Team
Feedback
See anything missing or incorrect?
Suggest an edit to this report.