blob: bbed588eef8d021ecab70b53b7cec643d3aa2ba2 [file] [log] [blame]
modules:
- module: github.com/gofiber/fiber
versions:
- fixed: 1.12.6
packages:
- package: github.com/gofiber/fiber
symbols:
- Ctx.Attachment
description: |
Due to improper input sanitization, a maliciously constructed filename
could cause a file download to use an attacker controlled filename, as well
as injecting additional headers into an HTTP response.
published: 2021-07-28T18:08:05Z
cves:
- CVE-2020-15111
ghsas:
- GHSA-9cx9-x2gp-9qvh
credit: Hasibul Hasan and Abdullah Shaleh
references:
- fix: https://github.com/gofiber/fiber/pull/579
- fix: https://github.com/gofiber/fiber/commit/f698b5d5066cfe594102ae252cd58a1fe57cf56f