CVE-2021-23772
24.12.2021, 12:15
This affects all versions of package github.com/kataras/iris; all versions of package github.com/kataras/iris/v12. The unsafe handling of file names during upload using UploadFormFiles method may enable attackers to write to arbitrary locations outside the designated target folder.
Vendor | Product | Version |
---|---|---|
iris-go | iris | 𝑥 ≤ 12.1.8 |
iris-go | iris | 12.2.0:alpha |
iris-go | iris | 12.2.0:alpha2 |
iris-go | iris | 12.2.0:alpha3 |
iris-go | iris | 12.2.0:alpha4 |
iris-go | iris | 12.2.0:alpha5 |
𝑥
= Vulnerable software versions
References