blob: 012bb6ff157e6157a097d09a64c6164e5b849b84 [file] [log] [blame]
id: GO-2024-2849
modules:
- module: github.com/dotmesh-io/dotmesh
unsupported_versions:
- last_affected: 0.8.1
vulnerable_at: 0.0.0-20200428140901-6bdf6885808f
summary: dotmesh arbitrary file read and/or write in github.com/dotmesh-io/dotmesh
cves:
- CVE-2020-26312
ghsas:
- GHSA-hf54-fq2m-p9v6
references:
- advisory: https://github.com/advisories/GHSA-hf54-fq2m-p9v6
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2020-26312
- advisory: https://securitylab.github.com/advisories/GHSL-2020-254-zipslip-dotmesh
- web: https://github.com/dotmesh-io/dotmesh/blob/master/pkg/archiver/tar.go#L255
source:
id: GHSA-hf54-fq2m-p9v6
created: 2024-06-04T14:27:24.630281-04:00
review_status: UNREVIEWED