Dismissed
by @LeSuisse Activity log
- Created automatic suggestion
-
@LeSuisse
removed
3 packages
- guile-fibers
- ocamlPackages.fiber
- ocamlPackages_latest.fiber
- @LeSuisse dismissed
Fiber has an Arbitrary File Read in Static Middleware on Windows
Fiber is an Express inspired web framework written in Go. A Path Traversal (CWE-22) vulnerability in Fiber allows a remote attacker to bypass the static middleware sanitizer and read arbitrary files on the server file system on Windows. This affects Fiber v3 through version 3.0.0. This has been patched in Fiber v3 version 3.1.0.
References
- https://github.com/gofiber/fiber/security/advisories/GHSA-m3c2-496v-cw3v x_refsource_CONFIRM
- https://github.com/gofiber/fiber/pull/4064 x_refsource_MISC
- https://github.com/gofiber/fiber/commit/59133702301c2ab7b776dd123b474cbd995f2c86 x_refsource_MISC
Affected products
fiber
- ==>= 3.0.0, < 3.1.0
Ignored packages (3)
pkgs.guile-fibers
Concurrent ML-like concurrency for Guile
pkgs.ocamlPackages.fiber
Structured concurrency library
pkgs.ocamlPackages_latest.fiber
Structured concurrency library