CVE-2021-23772
24.12.2021, 12:15
This affects all versions of package github.com/kataras/iris; all versions of package github.com/kataras/iris/v12. The unsafe handling of file names during upload using UploadFormFiles method may enable attackers to write to arbitrary locations outside the designated target folder.
| Vendor | Product | Version |
|---|---|---|
| iris-go | iris | 𝑥 ≤ 12.1.8 |
| iris-go | iris | 12.2.0:alpha |
| iris-go | iris | 12.2.0:alpha2 |
| iris-go | iris | 12.2.0:alpha3 |
| iris-go | iris | 12.2.0:alpha4 |
| iris-go | iris | 12.2.0:alpha5 |
𝑥
= Vulnerable software versions
References