Lucene search

K
osvGoogleOSV:GHSA-VPX7-VM66-QX8R
HistoryMay 18, 2021 - 8:31 p.m.

Path Traversal in github.com/unknwon/cae/zip

2021-05-1820:31:06
Google
osv.dev
8
path traversal
github.com/unknwon/cae/zip
extractto function
software vulnerability

EPSS

0.001

Percentile

43.5%

The ExtractTo function doesn’t securely escape file paths in zip archives which include leading or non-leading “…”. This allows an attacker to add or replace files system-wide.

Specific Go Packages Affected

github.com/unknwon/cae/zip

EPSS

0.001

Percentile

43.5%

Related for OSV:GHSA-VPX7-VM66-QX8R