—
GO-2024-3108
Hoverfly allows an arbitrary file read in the `/api/v2/simulation` endpoint (`GHSL-2023-274`) in github.com/SpectoLabs/hoverfly
Quick fix
GO-2024-3108 — github.com/SpectoLabs/hoverfly: upgrade to the fixed version with the command below.
go get github.com/SpectoLabs/hoverfly@v1.10.3Details
Hoverfly allows an arbitrary file read in the `/api/v2/simulation` endpoint (`GHSL-2023-274`) in github.com/SpectoLabs/hoverfly
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/SpectoLabs/hoverfly
Introduced in:
0Fixed in: 1.10.3Fix
go get github.com/SpectoLabs/hoverfly@v1.10.3References
- https://github.com/SpectoLabs/hoverfly/security/advisories/GHSA-6xx4-x46f-f897[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2024-45388[ADVISORY]
- https://codeql.github.com/codeql-query-help/go/go-path-injection[WEB]
- https://github.com/SpectoLabs/hoverfly/releases/tag/v1.10.3[WEB]
- https://github.com/spectolabs/hoverfly/blob/15d6ee9ea4e0de67aec5a41c28d21dc147243da0/core/handlers/v2/simulation_handler.go#L87[WEB]