First published: Fri Dec 24 2021(Updated: )
This affects all versions of package github.com/kataras/iris; all versions of package github.com/kataras/iris/v12. The unsafe handling of file names during upload using UploadFormFiles method may enable attackers to write to arbitrary locations outside the designated target folder.
Credit: report@snyk.io
Affected Software | Affected Version | How to fix |
---|---|---|
Iris Go | <=12.1.8 | |
Iris Go | =12.2.0-alpha | |
Iris Go | =12.2.0-alpha2 | |
Iris Go | =12.2.0-alpha3 | |
Iris Go | =12.2.0-alpha4 | |
Iris Go | =12.2.0-alpha5 | |
Go | <1.7.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.