VDB
Sign up
—

GO-2024-2702

Code injection vulnerability in github.com/flipped-aurora/gin-vue-admin/server

Quick fix

GO-2024-2702 — github.com/flipped-aurora/gin-vue-admin/server: upgrade to the fixed version with the command below.

go get github.com/flipped-aurora/gin-vue-admin/server@v0.0.0-20240409100909-b1b7427c6ea6

Details

Gin-vue-admin has a code injection vulnerability in the backend. In the Plugin System -> Plugin Template feature, an attacker can perform directory traversal by manipulating the 'plugName' parameter. They can create specific folders such as 'api', 'config', 'global', 'model', 'router', 'service', and 'main.go' function within the specified traversal directory. Moreover, the Go files within these folders can have arbitrary code inserted based on a specific PoC parameter.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/flipped-aurora/gin-vue-admin/server
Introduced in: 0Fixed in: 0.0.0-20240409100909-b1b7427c6ea6
Fixgo get github.com/flipped-aurora/gin-vue-admin/server@v0.0.0-20240409100909-b1b7427c6ea6

References