—
GO-2024-2702
Code injection vulnerability in github.com/flipped-aurora/gin-vue-admin/server
Quick fix
GO-2024-2702 — github.com/flipped-aurora/gin-vue-admin/server: upgrade to the fixed version with the command below.
go get github.com/flipped-aurora/gin-vue-admin/server@v0.0.0-20240409100909-b1b7427c6ea6Details
Gin-vue-admin has a code injection vulnerability in the backend. In the Plugin System -> Plugin Template feature, an attacker can perform directory traversal by manipulating the 'plugName' parameter. They can create specific folders such as 'api', 'config', 'global', 'model', 'router', 'service', and 'main.go' function within the specified traversal directory. Moreover, the Go files within these folders can have arbitrary code inserted based on a specific PoC parameter.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/flipped-aurora/gin-vue-admin/server
Introduced in:
0Fixed in: 0.0.0-20240409100909-b1b7427c6ea6Fix
go get github.com/flipped-aurora/gin-vue-admin/server@v0.0.0-20240409100909-b1b7427c6ea6