GHSA-wmpm-fq7r-jq56

Suggest an improvement
Source
https://github.com/advisories/GHSA-wmpm-fq7r-jq56
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/09/GHSA-wmpm-fq7r-jq56/GHSA-wmpm-fq7r-jq56.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-wmpm-fq7r-jq56
Aliases
  • CVE-2021-23427
Published
2021-09-02T22:05:17Z
Modified
2023-11-08T04:05:09.051868Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Imporoper path validation in elFinder.NetCore
Details

This affects all versions of package elFinder.NetCore. The ExtractAsync function within the FileSystem is vulnerable to arbitrary extraction due to insufficient validation.

Database specific
{
    "nvd_published_at": "2021-09-01T15:15:00Z",
    "github_reviewed_at": "2021-09-02T18:03:43Z",
    "severity": "CRITICAL",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-20"
    ]
}
References

Affected packages

NuGet / elFinder.NetCore

Package

Name
elFinder.NetCore
View open source insights on deps.dev
Purl
pkg:nuget/elFinder.NetCore

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
1.3.5

Affected versions

1.*

1.0.0
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
1.0.6
1.0.7
1.0.8
1.0.9
1.1.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5