—
GO-2023-1713
Path traversal in github.com/sjqzhang/go-fastdfs
Quick fix
GO-2023-1713 — github.com/sjqzhang/go-fastdfs: upgrade to the fixed version with the command below.
go get github.com/sjqzhang/go-fastdfs@v1.4.5-0.20230408141131-61cbff5124c6Details
An attacker can craft a remote request to upload a file to "/group1/upload" that uses path traversal to instead write the file contents to an attacker controlled path on the server.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/sjqzhang/go-fastdfs
Introduced in:
0Fixed in: 1.4.5-0.20230408141131-61cbff5124c6Fix
go get github.com/sjqzhang/go-fastdfs@v1.4.5-0.20230408141131-61cbff5124c6References
- https://github.com/yangyanglo/ForCVE/blob/93a16663cd32a36d37d8a0f0102e1592254d0279/2023-0x05.md[WEB]
- https://vuldb.com/?ctiid.224768[WEB]
- https://vuldb.com/?id.224768[WEB]
- https://github.com/sjqzhang/go-fastdfs/commit/61cbff5124c61e292994099372b11c06cdb5b80b[FIX]
- https://github.com/advisories/GHSA-xq3x-grrj-fj6x[ADVISORY]