blob: ca960153c65101a04706cb43d2c5d90b55cd9a9c [file] [log] [blame]
modules:
- module: github.com/gookit/goutil
versions:
- fixed: 0.6.7
vulnerable_at: 0.6.6
packages:
- package: github.com/gookit/goutil/fsutil
symbols:
- Unzip
description: |
fsutil.Unzip is vulnerable to path traversal attacks due to improper validation of paths.
cves:
- CVE-2023-27475
ghsas:
- GHSA-fx2v-qfhr-4chv
credit: '@cokeBeer'
references:
- advisory: https://github.com/gookit/goutil/security/advisories/GHSA-fx2v-qfhr-4chv
- fix: https://github.com/gookit/goutil/commit/d7b94fede71f018f129f7d21feb58c895d28dadc