VDB
Sign up
HIGH8.8

GHSA-5g39-ppwg-6xx8

Go-huge-util vulnerable to path traversal when unzipping files

Quick fix

GHSA-5g39-ppwg-6xx8 — github.com/dablelv/go-huge-util: upgrade to the fixed version with the command below.

go get github.com/dablelv/go-huge-util@v0.0.34

Details

Impact ZipSlip issue when use fsutil package to unzip files. When users use zip.Unzip to unzip zip files from a malicious attacker, they may be vulnerable to path traversal.

Patches It has been fixed in v0.0.34, Please upgrade version to v0.0.34 or above.

Workarounds No, users have to upgrade version.

Specific Go Packages Affected github.com/dablelv/go-huge-util/zip

References

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/dablelv/go-huge-util
Introduced in: 0Fixed in: 0.0.34
Fixgo get github.com/dablelv/go-huge-util@v0.0.34

References