x/vulndb: potential Go vuln in github.com/flipped-aurora/gin-vue-admin: CVE-2022-39305 #1076
Labels
excluded: EFFECTIVELY_PRIVATE
This vulnerability exists in a package can be imported, but isn't meant to be outside that module.
NeedsReport
CVE-2022-39305 references github.com/flipped-aurora/gin-vue-admin, which may be a Go module.
Description:
Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stack. Versions prior to 2.5.4 contain a file upload ability. The affected code fails to validate fileMd5 and fileName parameters, resulting in an arbitrary file being read. This issue is patched in 2.5.4b. There are no known workarounds.
References:
See doc/triage.md for instructions on how to triage this report.
The text was updated successfully, but these errors were encountered: