We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent 790329a commit 202a12dCopy full SHA for 202a12d
data/reports/GO-2021-0094.yaml
@@ -2,11 +2,11 @@ modules:
2
- module: github.com/hashicorp/go-slug
3
versions:
4
- fixed: 0.5.0
5
+ vulnerable_at: 0.4.3
6
packages:
7
- package: github.com/hashicorp/go-slug
8
symbols:
9
- Unpack
- skip_fix: 'TODO: fill this out [or set vulnerable_at to derive symbols]'
10
description: |
11
Protections against directory traversal during archive extraction can be
12
bypassed by chaining multiple symbolic links within the archive. This allows
0 commit comments