Headline
CVE-2020-7668: Arbitrary File Write via Archive Extraction (Zip Slip) in github.com/unknwon/cae/tz | Snyk
In all versions of the package github.com/unknwon/cae/tz, the ExtractTo function doesn’t securely escape file paths in zip archives which include leading or non-leading "…". This allows an attacker to add or replace files system-wide.
Attack Complexity
Low
Integrity
High
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications
snyk-id
SNYK-GOLANG-GITHUBCOMUNKNWONCAETZ-570384
published
5 Jun 2020
disclosed
26 May 2020
credit
Georgios Gkitsas of Snyk Security Team
How to fix?
Overview
Details
References