Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2020-7664: Arbitrary File Write via Archive Extraction (Zip Slip) in github.com/unknwon/cae/zip | Snyk

In all versions of the package github.com/unknwon/cae/zip, the ExtractTo function doesn’t securely escape file paths in zip archives which include leading or non-leading "…". This allows an attacker to add or replace files system-wide.

CVE
#ios#git
  • Attack Complexity

    Low

  • Integrity

    High

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

  • snyk-id

    SNYK-GOLANG-GITHUBCOMUNKNWONCAEZIP-570383

  • published

    5 Jun 2020

  • disclosed

    26 May 2020

  • credit

    Georgios Gkitsas of Snyk Security Team

How to fix?

Overview

Details

References

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907