Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Zip slip in Lancet
Vulnerability Description
Lancet is a general utility library for the go programming language. Affected versions are subject to a ZipSlip issue when using the fileutil package to unzip files. This issue has been addressed and a fix will be included in versions 2.1.10 and 1.3.4. Users are advised to upgrade. There are no known workarounds for this issue.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
Lancet 路径遍历漏洞
Vulnerability Description
Lancet是DuDaoDong个人开发者的一个全面、高效、可重用的 go 实用函数库。 Lancet v1.9.02.001 2.1.10 和 1.3.4版本存在路径遍历漏洞,该漏洞源于在使用 fileutil 包解压缩文件时会出现 ZipSlip 问题。
CVSS Information
N/A
Vulnerability Type
N/A