Vulnerability Report: GO-2023-2048
- GHSA-6xv5-86q9-7xr8
- Affects: github.com/cyphar/filepath-securejoin
- Published: Sep 13, 2023
- Modified: May 20, 2024
Certain rootfs and path combinations result in generated paths that are outside of the provided rootfs on Windows.
For detailed information about this vulnerability, visit https://github.com/cyphar/filepath-securejoin/security/advisories/GHSA-6xv5-86q9-7xr8.
Affected Packages
-
PathGo VersionsSymbols
-
before v0.2.4
Aliases
References
- https://github.com/cyphar/filepath-securejoin/security/advisories/GHSA-6xv5-86q9-7xr8
- https://github.com/cyphar/filepath-securejoin/commit/c121231e1276e11049547bee5ce68d5a2cfe2d9b
- https://vuln.go.dev/ID/GO-2023-2048.json
Credits
- @pjbgf
Feedback
See anything missing or incorrect?
Suggest an edit to this report.