HIGH8.8
GHSA-5g39-ppwg-6xx8
Go-huge-util vulnerable to path traversal when unzipping files
Quick fix
GHSA-5g39-ppwg-6xx8 — github.com/dablelv/go-huge-util: upgrade to the fixed version with the command below.
go get github.com/dablelv/go-huge-util@v0.0.34Details
Impact ZipSlip issue when use fsutil package to unzip files. When users use zip.Unzip to unzip zip files from a malicious attacker, they may be vulnerable to path traversal.
Patches It has been fixed in v0.0.34, Please upgrade version to v0.0.34 or above.
Workarounds No, users have to upgrade version.
Specific Go Packages Affected github.com/dablelv/go-huge-util/zip
References
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/dablelv/go-huge-util
Introduced in:
0Fixed in: 0.0.34Fix
go get github.com/dablelv/go-huge-util@v0.0.34References
- https://github.com/dablelv/go-huge-util/security/advisories/GHSA-5g39-ppwg-6xx8[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-28105[ADVISORY]
- https://github.com/dablelv/go-huge-util/commit/0e308b0fac8973e6fa251b0ab095cdc5c1c0956b[WEB]
- https://github.com/dablelv/go-huge-util[PACKAGE]
- https://pkg.go.dev/vuln/GO-2023-1640[WEB]