{"id":"CVE-2022-41920","summary":"Zip slip in Lancet","details":"Lancet is a general utility library for the go programming language. Affected versions are subject to a ZipSlip issue when using the fileutil package to unzip files. This issue has been addressed and a fix will be included in versions 2.1.10 and 1.3.4. Users are advised to upgrade. There are no known workarounds for this issue.","aliases":["GHSA-pp3f-xrw5-q5j4","GO-2022-1114"],"modified":"2026-04-10T04:51:50.546898Z","published":"2022-11-17T00:00:00Z","database_specific":{"cna_assigner":"GitHub_M","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/41xxx/CVE-2022-41920.json","cwe_ids":["CWE-22"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/41xxx/CVE-2022-41920.json"},{"type":"ADVISORY","url":"https://github.com/duke-git/lancet/security/advisories/GHSA-pp3f-xrw5-q5j4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-41920"},{"type":"REPORT","url":"https://github.com/duke-git/lancet/issues/62"},{"type":"FIX","url":"https://github.com/duke-git/lancet/commit/f133b32faa05eb93e66175d01827afa4b7094572"},{"type":"FIX","url":"https://github.com/duke-git/lancet/commit/f869a0a67098e92d24ddd913e188b32404fa72c9"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/duke-git/lancet","events":[{"introduced":"0"},{"fixed":"279d0754baaf8128460996782015cfccbe6a02eb"}],"database_specific":{"versions":[{"introduced":"0"},{"fixed":"1.3.4"}]}},{"type":"GIT","repo":"https://github.com/duke-git/lancet","events":[{"introduced":"40b2560752240140c49f89640686e633bb46b86e"},{"fixed":"2b17329094b480c65313c038fa36d3fd1b60f878"}],"database_specific":{"versions":[{"introduced":"2.0.0"},{"fixed":"2.1.10"}]}}],"versions":["v1.0.0","v1.0.1","v1.0.10","v1.0.2","v1.0.3","v1.0.4","v1.0.5","v1.0.6","v1.0.7","v1.0.8","v1.0.9","v1.1.0","v1.1.1","v1.1.10","v1.1.2","v1.1.3","v1.1.4","v1.1.5","v1.1.6","v1.1.7","v1.1.8","v1.1.9","v1.2.0","v1.2.1","v1.2.2","v1.2.3","v1.2.4","v1.2.5","v1.2.6","v1.2.7","v1.2.8","v1.2.9","v1.3.0","v1.3.1","v1.3.2","v1.3.3","v2.0.0","v2.0.1","v2.0.2","v2.0.3","v2.0.4","v2.0.5","v2.0.6","v2.0.7","v2.0.8","v2.0.9","v2.1.0","v2.1.1","v2.1.2","v2.1.3","v2.1.4","v2.1.5","v2.1.6","v2.1.7","v2.1.8","v2.1.9"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-41920.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L"}]}