CVE-2023-28105

HIGH

go-huge-util < 0.0.34 - Path Traversal via ZipSlip in fsutil Unzip

Title source: llm
STIX 2.1

Description

go-used-util has commonly used utility functions for Go. Versions prior to 0.0.34 have a ZipSlip issue when using fsutil package to unzip files. When users use `zip.Unzip` to unzip zip files from a malicious attacker, they may be vulnerable to path traversal. The issue has been fixed in version 0.0.34. There are no known workarounds.

Scores

CVSS v3 8.8
EPSS 0.0061
EPSS Percentile 44.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (2)
dablelv/go-huge-util 0 - 0.0.34Go
go-huge-util_project/go-huge-util < 0.0.34
Published Mar 16, 2023
Tracked Since Feb 18, 2026