—
GO-2024-3213
Plenti arbitrary file write vulnerability in github.com/plentico/plenti
Quick fix
GO-2024-3213 — github.com/plentico/plenti: upgrade to the fixed version with the command below.
go get github.com/plentico/plenti@v0.7.2Details
Plenti arbitrary file write vulnerability in github.com/plentico/plenti
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/plentico/plenti
Introduced in:
0Fixed in: 0.7.2Fix
go get github.com/plentico/plenti@v0.7.2References
- https://nvd.nist.gov/vuln/detail/CVE-2024-49380[ADVISORY]
- https://github.com/plentico/plenti/blob/01825e0dcd3505fac57adc2edf29f772d585c008/cmd/serve.go#L205[WEB]
- https://github.com/plentico/plenti/releases/tag/v0.7.2[WEB]
- https://securitylab.github.com/advisories/GHSL-2024-297_GHSL-2024-298_plenti/[WEB]