—
GO-2022-0787
Symbolic links in an unpacking routine may enable attackers to read and/or write to arbitrary locations in dbdeployer in github.com/datacharmer/dbdeployer
Quick fix
GO-2022-0787 — github.com/datacharmer/dbdeployer: upgrade to the fixed version with the command below.
go get github.com/datacharmer/dbdeployer@v1.58.2Details
Symbolic links in an unpacking routine may enable attackers to read and/or write to arbitrary locations in dbdeployer in github.com/datacharmer/dbdeployer
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/datacharmer/dbdeployer
Introduced in:
0Fixed in: 1.58.2Fix
go get github.com/datacharmer/dbdeployer@v1.58.2