HIGH8.8
GHSA-fx2v-qfhr-4chv
Goutil vulnerable to path traversal when unzipping files
Quick fix
GHSA-fx2v-qfhr-4chv — github.com/gookit/goutil: upgrade to the fixed version with the command below.
go get github.com/gookit/goutil@v0.6.0Details
### Impact
ZipSlip issue when use fsutil package to unzip files. When users use fsutil.Unzip to unzip zip files from a malicious attacker, they may be vulnerable to path traversal.
### Patches
It has been fixed in v0.6.0, Please upgrade version to v0.6.0 or above.
### Workarounds No, users have to upgrade version.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/gookit/goutil/security/advisories/GHSA-fx2v-qfhr-4chv[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-27475[ADVISORY]
- https://github.com/gookit/goutil/commit/d7b94fede71f018f129f7d21feb58c895d28dadc[WEB]
- https://github.com/gookit/goutil[PACKAGE]
- https://pkg.go.dev/vuln/GO-2023-1611[WEB]
- https://security.netapp.com/advisory/ntap-20230427-0003[WEB]