CVE-2022-41920
17.11.2022, 18:15
Lancet is a general utility library for the go programming language. Affected versions are subject to a ZipSlip issue when using the fileutil package to unzip files. This issue has been addressed and a fix will be included in versions 2.1.10 and 1.3.4. Users are advised to upgrade. There are no known workarounds for this issue.
Vendor | Product | Version |
---|---|---|
lancet_project | lancet | 𝑥 < 1.3.4 |
lancet_project | lancet | 2.0.0 ≤ 𝑥 < 2.1.10 |
𝑥
= Vulnerable software versions
References