{"id":"GHSA-pp3f-xrw5-q5j4","summary":"Lancet vulnerable to path traversal when unzipping files","details":"### Impact\n_What kind of vulnerability is it? Who is impacted?_\n\nZipSlip issue when use fileutil package to unzip files.\n\n### Patches\n_Has the problem been patched? What versions should users upgrade to?_\n\nIt will fixed in v2.1.10, Please upgrade version to v2.1.10 or above.\nUsers who use v1.x.x should upgrade v1.3.4 or above.\n\n### Workarounds\n_Is there a way for users to fix or remediate the vulnerability without upgrading?_\n\nNo, users have to upgrade version.","aliases":["CVE-2022-41920","GO-2022-1114"],"modified":"2023-11-01T05:00:06.144453Z","published":"2022-11-21T22:31:31Z","database_specific":{"github_reviewed_at":"2022-11-21T22:31:31Z","nvd_published_at":"2022-11-17T18:15:00Z","cwe_ids":["CWE-22"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/duke-git/lancet/security/advisories/GHSA-pp3f-xrw5-q5j4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-41920"},{"type":"WEB","url":"https://github.com/duke-git/lancet/issues/62"},{"type":"WEB","url":"https://github.com/duke-git/lancet/commit/f133b32faa05eb93e66175d01827afa4b7094572"},{"type":"WEB","url":"https://github.com/duke-git/lancet/commit/f869a0a67098e92d24ddd913e188b32404fa72c9"},{"type":"PACKAGE","url":"https://github.com/duke-git/lancet"},{"type":"WEB","url":"https://pkg.go.dev/vuln/GO-2022-1114"}],"affected":[{"package":{"name":"github.com/duke-git/lancet/v2","ecosystem":"Go","purl":"pkg:golang/github.com/duke-git/lancet/v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.0.0"},{"fixed":"2.1.10"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-pp3f-xrw5-q5j4/GHSA-pp3f-xrw5-q5j4.json"}},{"package":{"name":"github.com/duke-git/lancet","ecosystem":"Go","purl":"pkg:golang/github.com/duke-git/lancet"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.3.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-pp3f-xrw5-q5j4/GHSA-pp3f-xrw5-q5j4.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}