HIGH7.5
GHSA-jcxc-rh6w-wf49
Link Following in Iris
Quick fix
GHSA-jcxc-rh6w-wf49 — github.com/kataras/iris/v12: upgrade to the fixed version with the command below.
go get github.com/kataras/iris/v12@v12.2.0-alpha8Details
This affects all versions of package github.com/kataras/iris; all versions of package github.com/kataras/iris/v12. The unsafe handling of file names during upload using UploadFormFiles method may enable attackers to write to arbitrary locations outside the designated target folder.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/kataras/iris/v12
Introduced in:
0Fixed in: 12.2.0-alpha8Fix
go get github.com/kataras/iris/v12@v12.2.0-alpha8Go/github.com/kataras/iris
Introduced in:
0No fixed version published yet for github.com/kataras/iris (go modules). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-23772[ADVISORY]
- https://github.com/kataras/iris/commit/e213dba0d32ff66653e0ef124bc5088817264b08[WEB]
- https://github.com/kataras/iris[PACKAGE]
- https://pkg.go.dev/vuln/GO-2022-0272[WEB]
- https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMKATARASIRIS-2325169[WEB]
- https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMKATARASIRISV12-2325170[WEB]