{"id":"GO-2021-0091","details":"Due to improper input validation when uploading a file, a malicious user may\nforce the server to return arbitrary HTTP headers when the uploaded\nfile is downloaded.\n","modified":"2022-08-29T16:50:59Z","published":"2021-04-14T20:04:52Z","withdrawn":"2024-05-15T05:37:10.999237Z","references":[{"type":"FIX","url":"https://github.com/gofiber/fiber/pull/579"},{"type":"FIX","url":"https://github.com/gofiber/fiber/commit/a8ad5454363f627c3f9469c56c5faaf1b943f06a"},{"type":"WEB","url":"https://github.com/gofiber/fiber/security/advisories/GHSA-9cx9-x2gp-9qvh"}],"affected":[{"package":{"name":"github.com/gofiber/fiber","ecosystem":"Go","purl":"pkg:golang/github.com/gofiber/fiber"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.12.6-0.20200710202935-a8ad5454363f"}]}],"ecosystem_specific":{"imports":[{"path":"github.com/gofiber/fiber","symbols":["Ctx.Attachment"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2021-0091.json","url":"https://pkg.go.dev/vuln/GO-2021-0091"}}],"schema_version":"1.7.3"}