CRITICAL9.8
GHSA-q5mg-pc7r-r8cr
Files or Directories Accessible to External Parties in ProjectDiscovery
Quick fix
GHSA-q5mg-pc7r-r8cr — github.com/projectdiscovery/interactsh: upgrade to the fixed version with the command below.
go get github.com/projectdiscovery/interactsh@v1.2.0Details
Files or Directories Accessible to External Parties vulnerability in smb server in ProjectDiscovery Interactsh allows remote attackers to read/write any files in the directory and subdirectories of where the victim runs interactsh-server via anonymous login.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/projectdiscovery/interactsh
Introduced in:
0Fixed in: 1.2.0Fix
go get github.com/projectdiscovery/interactsh@v1.2.0References
- https://nvd.nist.gov/vuln/detail/CVE-2024-5262[ADVISORY]
- https://github.com/projectdiscovery/interactsh/pull/874[WEB]
- https://github.com/projectdiscovery/interactsh/commit/6a0cb98b16636a98712729f3d23e34d8bf7260e7[WEB]
- https://github.com/projectdiscovery/interactsh[PACKAGE]
- https://pkg.go.dev/vuln/GO-2024-2907[WEB]
- https://zuso.ai/advisory/za-2024-01[WEB]