Vulnerability Description
Lancet is a general utility library for the go programming language. Affected versions are subject to a ZipSlip issue when using the fileutil package to unzip files. This issue has been addressed and a fix will be included in versions 2.1.10 and 1.3.4. Users are advised to upgrade. There are no known workarounds for this issue.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lancet Project | Lancet | < 1.3.4 |
Related Weaknesses (CWE)
References
- https://github.com/duke-git/lancet/commit/f133b32faa05eb93e66175d01827afa4b70945PatchThird Party Advisory
- https://github.com/duke-git/lancet/commit/f869a0a67098e92d24ddd913e188b32404fa72PatchThird Party Advisory
- https://github.com/duke-git/lancet/issues/62Issue TrackingThird Party Advisory
- https://github.com/duke-git/lancet/security/advisories/GHSA-pp3f-xrw5-q5j4ExploitThird Party Advisory
- https://github.com/duke-git/lancet/commit/f133b32faa05eb93e66175d01827afa4b70945PatchThird Party Advisory
- https://github.com/duke-git/lancet/commit/f869a0a67098e92d24ddd913e188b32404fa72PatchThird Party Advisory
- https://github.com/duke-git/lancet/issues/62Issue TrackingThird Party Advisory
- https://github.com/duke-git/lancet/security/advisories/GHSA-pp3f-xrw5-q5j4ExploitThird Party Advisory
FAQ
What is CVE-2022-41920?
CVE-2022-41920 is a vulnerability with a CVSS score of 6.3 (MEDIUM). Lancet is a general utility library for the go programming language. Affected versions are subject to a ZipSlip issue when using the fileutil package to unzip files. This issue has been addressed and ...
How severe is CVE-2022-41920?
CVE-2022-41920 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-41920?
Check the references section above for vendor advisories and patch information. Affected products include: Lancet Project Lancet.