sjqzhang go-fastdfs up to 1.4.3 is vulnerable to path traversal in the function upload of the file /group1/upload of the component File Upload Handler. The attack may be launched remotely and the exploit has been disclosed to the public and may be used.
{
"nvd_published_at": "2023-04-02T11:15:00Z",
"cwe_ids": [
"CWE-22",
"CWE-24",
"CWE-434"
],
"severity": "CRITICAL",
"github_reviewed": true,
"github_reviewed_at": "2023-04-07T22:24:59Z"
}