CVE-2023-28105

go-used-util has commonly used utility functions for Go. Versions prior to 0.0.34 have a ZipSlip issue when using fsutil package to unzip files. When users use `zip.Unzip` to unzip zip files from a malicious attacker, they may be vulnerable to path traversal. The issue has been fixed in version 0.0.34. There are no known workarounds.
CVSS

No CVSS.

Advertisement

NeevaHost hosting service

Configurations

No configuration.

Information

Published : 2023-03-16 10:15

Updated : 2023-03-16 11:40


NVD link : CVE-2023-28105

Mitre link : CVE-2023-28105


JSON object : View

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Advertisement

dedicated server usa

Products Affected

No product.