blob: 75f44d707255cb980eaf464e8c378d5945ec14e0 [file] [log] [blame]
id: GO-2024-3251
modules:
- module: github.com/google/safearchive
versions:
- fixed: 0.0.0-20241025131057-f7ce9d7b6f9c
summary: Safearchive Path Traversal vulnerability in github.com/google/safearchive
cves:
- CVE-2024-10389
ghsas:
- GHSA-q3rp-vvm7-j8jg
references:
- advisory: https://github.com/advisories/GHSA-q3rp-vvm7-j8jg
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2024-10389
- fix: https://github.com/google/safearchive/commit/f7ce9d7b6f9c6ecd72d0b0f16216b046e55e44dc
notes:
- fix: 'github.com/google/safearchive: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version'
source:
id: GHSA-q3rp-vvm7-j8jg
created: 2024-11-06T11:55:09.66027-05:00
review_status: UNREVIEWED