8000 x/vulndb: potential Go vuln in github.com/gin-gonic/gin: CVE-2023-29401 · Issue #1737 · golang/vulndb · GitHub
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content
x/vulndb: potential Go vuln in github.com/gin-gonic/gin: CVE-2023-29401 #1737
Closed
@motoyasu-saburi

Description

@motoyasu-saburi

Description

Gin is a web framework written in Go.
Gin prior to version v1.9.0 and below is vulnerable to Reflect File Download.
This problem occurs when FileAttachment() is used.
A PullRequest to correct this problem has been provided but has not yet been fixed.

Affected Modules, Packages, Versions and Symbols

Module: github.com/gin-gonic/gin
Package: github.com/gin-gonic/gin
Versions:
  - Introduced: 1.9.0
Symbols:
  - FileAttachment

Does this vulnerability already have an associated CVE ID?

No

CVE ID

No response

Credit

No response

CWE ID

No response

Pull Request

gin-gonic/gin#3556

Commit

No response

References

Report:
gin-gonic/gin#3555

Additional information

No response

Metadata

Metadata

Assignees

Type

No type

Proje 306A cts

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions

    0