VDB
Sign up
—

GO-2023-1713

Path traversal in github.com/sjqzhang/go-fastdfs

Quick fix

GO-2023-1713 — github.com/sjqzhang/go-fastdfs: upgrade to the fixed version with the command below.

go get github.com/sjqzhang/go-fastdfs@v1.4.5-0.20230408141131-61cbff5124c6

Details

An attacker can craft a remote request to upload a file to "/group1/upload" that uses path traversal to instead write the file contents to an attacker controlled path on the server.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/sjqzhang/go-fastdfs
Introduced in: 0Fixed in: 1.4.5-0.20230408141131-61cbff5124c6
Fixgo get github.com/sjqzhang/go-fastdfs@v1.4.5-0.20230408141131-61cbff5124c6

References