GO-2023-2011
Dashboard / Vulnerabilities / GO-2023-2011
GO-2023-2011
Published: 21 Aug 2024Last Modified: 3 Mar 2026
Aliases:
Summary: Yaklang Plugin's Fuzztag Component Allows Unauthorized Local File Reading in github.com/yaklang/yaklang
Details: Yaklang Plugin's Fuzztag Component Allows Unauthorized Local File Reading in github.com/yaklang/yaklang
References: https://github.com/yaklang/yaklang/security/advisories/GHSA-xvhg-w6qc-m3qq, https://nvd.nist.gov/vuln/detail/CVE-2023-40023, https://github.com/yaklang/yaklang/pull/295, https://github.com/yaklang/yaklang/pull/296, https://mp.weixin.qq.com/s?__biz=Mzg5ODE3NTU1OQ==&mid=2247484236&idx=1&sn=ef0c14a89721800b2311d0e487388399
Affected packages
Package
Name: github.com/yaklang/yaklang
Purl: pkg:golang/github.com/yaklang/yaklang
Affected ranges
Type: SEMVER
Events:
Introduced- 0
Fixed -1.2.4-sp2
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
