VYPR
High severity7.5OSV Advisory· Published Dec 24, 2021· Updated Jun 17, 2026

CVE-2021-23772

CVE-2021-23772

Description

This affects all versions of package github.com/kataras/iris; all versions of package github.com/kataras/iris/v12. The unsafe handling of file names during upload using UploadFormFiles method may enable attackers to write to arbitrary locations outside the designated target folder.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/kataras/iris/v12Go
< 12.2.0-alpha812.2.0-alpha8
github.com/kataras/irisGo
<= 0.0.2

Affected products

9
  • Range: v12.0.0, v12.0.1, v12.1.1, …
  • Iris Go/Iris6 versions
    cpe:2.3:a:iris-go:iris:*:*:*:*:*:go:*:*+ 5 more
    • cpe:2.3:a:iris-go:iris:*:*:*:*:*:go:*:*range: <=12.1.8
    • cpe:2.3:a:iris-go:iris:12.2.0:alpha2:*:*:*:go:*:*
    • cpe:2.3:a:iris-go:iris:12.2.0:alpha3:*:*:*:go:*:*
    • cpe:2.3:a:iris-go:iris:12.2.0:alpha4:*:*:*:go:*:*
    • cpe:2.3:a:iris-go:iris:12.2.0:alpha5:*:*:*:go:*:*
    • cpe:2.3:a:iris-go:iris:12.2.0:alpha:*:*:*:go:*:*
  • ghsa-coords2 versions
    <= 0.0.2+ 1 more
    • (no CPE)range: <= 0.0.2
    • (no CPE)range: < 12.2.0-alpha8

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.