{"id":"GHSA-hj4g-4w36-x8hp","summary":"Kraken has arbitrary file read vulnerability via component testfs","details":"kraken \u003c= 0.1.4 has an arbitrary file read vulnerability via the component `testfs`.","aliases":["CVE-2022-47747","GO-2023-1505"],"modified":"2025-04-04T02:08:51Z","published":"2023-01-20T18:30:22Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2023-01-20T21:56:09Z","nvd_published_at":"2023-01-20T17:15:00Z","cwe_ids":["CWE-22"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-47747"},{"type":"WEB","url":"https://github.com/uber/kraken/issues/333"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-hj4g-4w36-x8hp"},{"type":"PACKAGE","url":"https://github.com/uber/kraken"}],"affected":[{"package":{"name":"github.com/uber/kraken","ecosystem":"Go","purl":"pkg:golang/github.com/uber/kraken"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"0.1.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-hj4g-4w36-x8hp/GHSA-hj4g-4w36-x8hp.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}