blob: 8bc62ac73586a2224ece7388a9521e7603619601 [file] [log] [blame]
id: GO-2023-2011
modules:
- module: github.com/yaklang/yaklang
versions:
- fixed: 1.2.4-sp2
vulnerable_at: 1.2.4-sp1
summary: Yaklang Plugin's Fuzztag Component Allows Unauthorized Local File Reading in github.com/yaklang/yaklang
cves:
- CVE-2023-40023
ghsas:
- GHSA-xvhg-w6qc-m3qq
references:
- advisory: https://github.com/yaklang/yaklang/security/advisories/GHSA-xvhg-w6qc-m3qq
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2023-40023
- fix: https://github.com/yaklang/yaklang/pull/295
- fix: https://github.com/yaklang/yaklang/pull/296
- web: https://mp.weixin.qq.com/s?__biz=Mzg5ODE3NTU1OQ==&mid=2247484236&idx=1&sn=ef0c14a89721800b2311d0e487388399
source:
id: GHSA-xvhg-w6qc-m3qq
created: 2024-08-20T12:00:40.607378-04:00
review_status: UNREVIEWED
unexcluded: EFFECTIVELY_PRIVATE