GO-2023-2048
Dashboard / Vulnerabilities / GO-2023-2048
Summary: Paths outside of the rootfs could be produced on Windows in github.com/cyphar/filepath-securejoin
Details: Certain rootfs and path combinations result in generated paths that are outside of the provided rootfs on Windows.
References: https://github.com/cyphar/filepath-securejoin/security/advisories/GHSA-6xv5-86q9-7xr8, https://github.com/cyphar/filepath-securejoin/commit/c121231e1276e11049547bee5ce68d5a2cfe2d9b
Affected packages
Package
Name: github.com/cyphar/filepath-securejoin
Purl: pkg:golang/github.com/cyphar/filepath-securejoin
Affected ranges
Type: SEMVER
Events:
Introduced- 0
Fixed -0.2.4
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
