—
GO-2023-1809
go package pydio cells vulnerable to cross-site scripting in github.com/pydio/cells
Quick fix
GO-2023-1809 — github.com/pydio/cells/v4: upgrade to the fixed version with the command below.
go get github.com/pydio/cells/v4@v4.2.1Details
go package pydio cells vulnerable to cross-site scripting in github.com/pydio/cells
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/pydio/cells
Introduced in:
0No fixed version published yet for github.com/pydio/cells (go modules). Pin to a known-safe version or switch to an alternative.
Go/github.com/pydio/cells/v4
Introduced in:
0Fixed in: 4.2.1Fix
go get github.com/pydio/cells/v4@v4.2.1References
- https://github.com/advisories/GHSA-wmfc-g86p-fjvr[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2023-2981[ADVISORY]
- https://popalltheshells.medium.com/multiple-cves-affecting-pydio-cells-4-2-0-321e7e4712be[WEB]
- https://pydio.com/en/community/releases/pydio-cells/pydio-cells-enterprise-421[WEB]
- https://vuldb.com/?ctiid.230213[WEB]
- https://vuldb.com/?id.230213[WEB]