CVE-2020-36560 Information
Dec 28, 2022
cve
Description
Due to improper path santization archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory.
Reference
https://github.com/artdarek/go-unzip/pull/2 https://pkg.go.dev/vuln/GO-2020-0034 https://snyk.io/research/zip-slip-vulnerability https://github.com/artdarek/go-unzip/commit/4975cbe0a719dc50b12da8585f1f207c82f7dfe0
Share on: