{"id":"GHSA-xq3x-grrj-fj6x","summary":"sjqzhang go-fastdfs vulnerable to path traversal","details":"sjqzhang go-fastdfs up to 1.4.3 is vulnerable to path traversal in the function upload of the file `/group1/upload` of the component `File Upload Handler`. The attack may be launched remotely and the exploit has been disclosed to the public and may be used.","aliases":["CVE-2023-1800","GO-2023-1713"],"modified":"2024-05-20T21:50:28Z","published":"2023-04-02T12:30:16Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2023-04-07T22:24:59Z","nvd_published_at":"2023-04-02T11:15:00Z","cwe_ids":["CWE-22","CWE-24","CWE-434"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-1800"},{"type":"WEB","url":"https://github.com/sjqzhang/go-fastdfs/commit/61cbff5124c61e292994099372b11c06cdb5b80b"},{"type":"PACKAGE","url":"https://github.com/sjqzhang/go-fastdfs"},{"type":"WEB","url":"https://github.com/yangyanglo/ForCVE/blob/93a16663cd32a36d37d8a0f0102e1592254d0279/2023-0x05.md"},{"type":"WEB","url":"https://github.com/yangyanglo/ForCVE/blob/main/2023-0x05.md"},{"type":"WEB","url":"https://vuldb.com/?ctiid.224768"},{"type":"WEB","url":"https://vuldb.com/?id.224768"}],"affected":[{"package":{"name":"github.com/sjqzhang/go-fastdfs","ecosystem":"Go","purl":"pkg:golang/github.com/sjqzhang/go-fastdfs"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.4.5-0.20230408141131-61cbff5124c6"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/04/GHSA-xq3x-grrj-fj6x/GHSA-xq3x-grrj-fj6x.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}