GO-2021-0094
Dashboard / Vulnerabilities / GO-2021-0094
GO-2021-0094
Summary: Directory traversal in github.com/hashicorp/go-slug
Details: Protections against directory traversal during archive extraction can be bypassed by chaining multiple symbolic links within the archive. This allows a malicious attacker to cause files to be created outside of the target directory. Additionally if the attacker is able to read extracted files they may create symbolic links to arbitrary files on the system which the unpacker has permissions to read.
References: https://github.com/hashicorp/go-slug/pull/12, https://github.com/hashicorp/go-slug/commit/28cafc59c8da6126a3ae94dfa84181df4073454f, https://securitylab.github.com/advisories/GHSL-2020-262-zipslip-go-slug
Affected packages
Package
Name: github.com/hashicorp/go-slug
Purl: pkg:golang/github.com/hashicorp/go-slug
Affected ranges
Type: SEMVER
Events:
