GHSA-6xv5-86q9-7xr8
SecureJoin: on windows, paths outside of the rootfs could be inadvertently produced
Quick fix
GHSA-6xv5-86q9-7xr8 — github.com/cyphar/filepath-securejoin: upgrade to the fixed version with the command below.
go get github.com/cyphar/filepath-securejoin@v0.2.4Details
### Impact For Windows users of `github.com/cyphar/filepath-securejoin`, until v0.2.4 it was possible for certain rootfs and path combinations (in particular, where a malicious Unix-style `/`-separated unsafe path was used with a Windows-style rootfs path) to result in generated paths that were outside of the provided rootfs.
It is unclear to what extent this has a practical impact on real users, but given the possible severity of the issue we have released an emergency patch release that resolves this issue.
Thanks to @pjbgf for discovering, debugging, and fixing this issue (as well as writing some tests for it).
### Patches c121231e1276e11049547bee5ce68d5a2cfe2d9b is the patch fixing this issue. v0.2.4 contains the fix.
### Workarounds Users could use `filepath.FromSlash()` on all unsafe paths before passing them to `filepath-securejoin`.
### References See #9.
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 0.2.4go get github.com/cyphar/filepath-securejoin@v0.2.4References
- https://github.com/cyphar/filepath-securejoin/security/advisories/GHSA-6xv5-86q9-7xr8[WEB]
- https://github.com/cyphar/filepath-securejoin/pull/9[WEB]
- https://github.com/cyphar/filepath-securejoin/commit/c121231e1276e11049547bee5ce68d5a2cfe2d9b[WEB]
- https://github.com/cyphar/filepath-securejoin[PACKAGE]
- https://github.com/cyphar/filepath-securejoin/releases/tag/v0.2.4[WEB]