CRITICAL9.8
GHSA-wmpm-fq7r-jq56
Imporoper path validation in elFinder.NetCore
Details
This affects all versions of package elFinder.NetCore. The ExtractAsync function within the FileSystem is vulnerable to arbitrary extraction due to insufficient validation.
Are you affected?
Enter the version of the package you're using.
Affected packages
NuGet/elFinder.NetCore
Introduced in:
0No fixed version published yet for elFinder.NetCore (nuget). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-23427[ADVISORY]
- https://github.com/gordon-matt/elFinder.NetCore[PACKAGE]
- https://github.com/gordon-matt/elFinder.NetCore/blob/633da9a4d7d5c9baefd1730ee51bf7af54889600/elFinder.NetCore/Drivers/FileSystem/FileSystemDriver.cs#L226[WEB]
- https://github.com/gordon-matt/elFinder.NetCore/blob/633da9a4d7d5c9baefd1730ee51bf7af54889600/elFinder.NetCore/Drivers/FileSystem/FileSystemDriver.cs%23L226[WEB]
- https://snyk.io/vuln/SNYK-DOTNET-ELFINDERNETCORE-1567778[WEB]