—
GO-2024-3283
SFTPGo allows administrators to restrict command execution from the EventManager in github.com/drakkan/sftpgo
Quick fix
GO-2024-3283 — github.com/drakkan/sftpgo/v2: upgrade to the fixed version with the command below.
go get github.com/drakkan/sftpgo/v2@v2.6.3Details
SFTPGo allows administrators to restrict command execution from the EventManager in github.com/drakkan/sftpgo
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/drakkan/sftpgo
Introduced in:
0No fixed version published yet for github.com/drakkan/sftpgo (go modules). Pin to a known-safe version or switch to an alternative.
Go/github.com/drakkan/sftpgo/v2
Introduced in:
2.4.0Fixed in: 2.6.3Fix
go get github.com/drakkan/sftpgo/v2@v2.6.3References
- https://nvd.nist.gov/vuln/detail/CVE-2024-52309[ADVISORY]
- https://github.com/drakkan/sftpgo/commit/88b1850b5806eee81150873d4e565144b21021fb[FIX]
- https://github.com/drakkan/sftpgo/commit/b524da11e9466d05fe03304713ee1c61bb276ec4[FIX]
- https://github.com/drakkan/sftpgo/security/advisories/GHSA-49cc-xrjf-9qf7[WEB]