HIGH 7.5 Go
github.com/sassoftware/go-rpmutils Arbitrary File Write via Archive Extraction (Zip Slip)
GHSA-9423-6c93-gpp8 · CVE-2020-7667 · GO-2020-0042 · SNYK-GOLANG-GITHUBCOMSASSOFTWAREGORPMUTILSCPIO-570427
Published · Modified
Description
The CPIO extraction functionality doesn't sanitize the paths of the archived files for leading and non-leading .. which leads in file extraction outside of the current directory. Note, the fixing commit was applied to all affected versions which were re-released.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2020-7667
- WEB https://github.com/sassoftware/go-rpmutils/commit/a64058cf21b8aada501bba923c9aab66fb6febf0
- PACKAGE https://github.com/sassoftware/go-rpmutils
- WEB https://pkg.go.dev/vuln/GO-2020-0042
- WEB https://snyk.io/research/zip-slip-vulnerability
- WEB https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMSASSOFTWAREGORPMUTILSCPIO-570427
Ready to move
Start Securing
Free, no credit card | First findings in minutes