CVE-2020-36561 Information
Dec 28, 2022
cve
Description
Due to improper path santization archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory.
Reference
https://github.com/yi-ge/unzip/commit/2adbaa4891b9690853ef10216189189f5ad7dc73 https://pkg.go.dev/vuln/GO-2020-0035 https://github.com/yi-ge/unzip/pull/1 https://snyk.io/research/zip-slip-vulnerability
Share on: