{"id":"GHSA-2x48-p6cq-5xcw","summary":"Path Traversal in github.com/go-sonic/sonic","details":"An issue in the component /admin/backups/work-dir of Sonic v1.0.4 allows attackers to execute a directory traversal.","aliases":["CVE-2022-46959","GO-2023-1509"],"modified":"2024-08-20T20:58:59.460214Z","published":"2023-01-23T06:30:20Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2023-01-23T20:37:57Z","nvd_published_at":"2023-01-23T05:15:00Z","cwe_ids":["CWE-22"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-46959"},{"type":"WEB","url":"https://github.com/go-sonic/sonic/issues/56"},{"type":"WEB","url":"https://github.com/go-sonic/sonic/pull/61/commits/3b00266a13fa69284f4b3f4b37d29be8f8e02f31"},{"type":"PACKAGE","url":"https://github.com/go-sonic/sonic"},{"type":"WEB","url":"https://github.com/go-sonic/sonic/releases/tag/v1.0.5"}],"affected":[{"package":{"name":"github.com/go-sonic/sonic","ecosystem":"Go","purl":"pkg:golang/github.com/go-sonic/sonic"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.0.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-2x48-p6cq-5xcw/GHSA-2x48-p6cq-5xcw.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}