GO-2023-1713
Dashboard / Vulnerabilities / GO-2023-1713
GO-2023-1713
Published: 12 Apr 2023Last Modified: 20 May 2024
Aliases:
Summary: Path traversal in github.com/sjqzhang/go-fastdfs
Details: An attacker can craft a remote request to upload a file to "/group1/upload" that uses path traversal to instead write the file contents to an attacker controlled path on the server.
References: https://github.com/yangyanglo/ForCVE/blob/93a16663cd32a36d37d8a0f0102e1592254d0279/2023-0x05.md, https://vuldb.com/?ctiid.224768, https://vuldb.com/?id.224768, https://github.com/sjqzhang/go-fastdfs/commit/61cbff5124c61e292994099372b11c06cdb5b80b, https://github.com/advisories/GHSA-xq3x-grrj-fj6x
Affected packages
Package
Name: github.com/sjqzhang/go-fastdfs
Purl: pkg:golang/github.com/sjqzhang/go-fastdfs
Affected ranges
Type: SEMVER
Events:
Introduced- 0
Fixed -1.4.5-0.20230408141131-61cbff5124c6
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
