You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
See doc/triage.md for instructions on how to triage this report.
packages:
- package: github.com/beego/beego
versions:
- introduced: TODO (earliest fixed "", vuln range "< 2.0.2")
- package: github.com/beego/beego/v2
versions:
- introduced: 2.0.0
fixed: 2.0.2
description: beego is an open-source, high-performance web framework for the Go programming
language. An issue was discovered in file profile.go in function GetCPUProfile
in beego through 2.0.2, allows attackers to launch symlink attacks locally.
published: 2022-04-06T00:01:30Z
last_modified: 2022-04-15T03:08:39Z
cves:
- CVE-2021-27117
ghsas:
- GHSA-2v6v-q994-xvxx
links:
context:
- https://github.com/advisories/GHSA-2v6v-q994-xvxx
The text was updated successfully, but these errors were encountered:
In GitHub Security Advisory GHSA-2v6v-q994-xvxx, there is a vulnerability in the following Go packages or modules:
See doc/triage.md for instructions on how to triage this report.
The text was updated successfully, but these errors were encountered: