—
GO-2022-1204
Yapscan's report receiver server vulnerable to path traversal and log injection in github.com/fkie-cad/yapscan
Quick fix
GO-2022-1204 — github.com/fkie-cad/yapscan: upgrade to the fixed version with the command below.
go get github.com/fkie-cad/yapscan@v0.19.1Details
Yapscan's report receiver server vulnerable to path traversal and log injection in github.com/fkie-cad/yapscan
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/fkie-cad/yapscan
Introduced in:
0.18.0Fixed in: 0.19.1Fix
go get github.com/fkie-cad/yapscan@v0.19.1References
- https://github.com/fkie-cad/yapscan/security/advisories/GHSA-9h6h-9g78-86f7[ADVISORY]
- https://github.com/fkie-cad/yapscan/commit/a75a20b50be673b96b1d42187b97f8cfe60728df[FIX]
- https://github.com/fkie-cad/yapscan/commit/fef9a33ceb66f6b929839f7eaf393b629681bc5d[FIX]
- https://github.com/fkie-cad/yapscan/issues/35[REPORT]
- https://github.com/fkie-cad/yapscan/releases/tag/v0.19.1[WEB]