Lucene search

K
osvGoogleOSV:GO-2021-0228
HistoryJan 14, 2022 - 5:30 p.m.

Path traversal in github.com/unknwon/cae

2022-01-1417:30:28
Google
osv.dev
5
path traversal
zip archives
file manipulation
security vulnerability
github

EPSS

0.001

Percentile

43.5%

The ExtractTo function doesn’t securely escape file paths in zip archives which include leading or non-leading “…”. This allows an attacker to add or replace files system-wide.

EPSS

0.001

Percentile

43.5%