GO-2022-0787
Dashboard / Vulnerabilities / GO-2022-0787
GO-2022-0787
Published: 21 Aug 2024Last Modified: 3 Mar 2026
Aliases:
Summary: Symbolic links in an unpacking routine may enable attackers to read and/or write to arbitrary locations in dbdeployer in github.com/datacharmer/dbdeployer
Details: Symbolic links in an unpacking routine may enable attackers to read and/or write to arbitrary locations in dbdeployer in github.com/datacharmer/dbdeployer
References: https://github.com/datacharmer/dbdeployer/security/advisories/GHSA-47wr-426j-fr82, https://nvd.nist.gov/vuln/detail/CVE-2020-26277, https://github.com/datacharmer/dbdeployer/commit/548e256c1de2f99746e861454e7714ec6bc9bb10
Affected packages
Package
Name: github.com/datacharmer/dbdeployer
Purl: pkg:golang/github.com/datacharmer/dbdeployer
Affected ranges
Type: SEMVER
Events:
Introduced- 0
Fixed -1.58.2
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
