PT-2023-21563 · Unknown · Go-Used-Util

Cokebeer

·

Publicado

2023-03-16

·

Atualizado

2023-08-23

·

CVE-2023-28105

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions go-used-util versions prior to 0.0.34
Description The issue is a ZipSlip problem that occurs when using the fsutil package to unzip files. This can lead to path traversal when users use zip.Unzip to unzip zip files from a malicious attacker.
Recommendations For versions prior to 0.0.34, upgrade to version 0.0.34 or above to fix the issue. As a temporary workaround, consider avoiding the use of the zip.Unzip function from the github.com/dablelv/go-huge-util/zip package until the upgrade is applied.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-28105
GHSA-5G39-PPWG-6XX8
GO-2023-1640

Produtos afetados

Go-Used-Util