VDB
Sign up
—

GO-2022-1015

SFTPGo WebClient vulnerable to Cross-site Scripting in github.com/drakkan/sftpgo

Quick fix

GO-2022-1015 — github.com/drakkan/sftpgo/v2: upgrade to the fixed version with the command below.

go get github.com/drakkan/sftpgo/v2@v2.3.5

Details

SFTPGo WebClient vulnerable to Cross-site Scripting in github.com/drakkan/sftpgo

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/drakkan/sftpgo
Introduced in: 0

No fixed version published yet for github.com/drakkan/sftpgo (go modules). Pin to a known-safe version or switch to an alternative.

Go/github.com/drakkan/sftpgo/v2
Introduced in: 0Fixed in: 2.3.5
Fixgo get github.com/drakkan/sftpgo/v2@v2.3.5

References