CVE-2023-29401
Description
The filename parameter of the Context.FileAttachment function is not properly sanitized. A maliciously crafted filename can cause the Content-Disposition header to be sent with an unexpected filename value or otherwise modify the Content-Disposition header. For example, a filename of "setup.bat";x=.txt" will be sent as a file named "setup.bat". If the FileAttachment function is called with names provided by an untrusted source, this may permit an attacker to cause a file to be served with a name different than provided. Maliciously crafted attachment file name can modify the Content-Disposition header.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/gin-gonic/ginGo | >= 1.3.1-0.20190301021747-ccb9e902956d, < 1.9.1 | 1.9.1 |
Affected products
3- ghsa-coordsRange: >= 1.3.1-0.20190301021747-ccb9e902956d, < 1.9.1
- github.com/gin-gonic/gin/github.com/gin-gonic/ginv5Range: 1.3.1-0.20190301021747-ccb9e902956d
Patches
Vulnerability mechanics
References
6- github.com/gin-gonic/gin/pull/3556nvdIssue TrackingPatchWEB
- github.com/gin-gonic/gin/issues/3555nvdExploitIssue TrackingWEB
- github.com/advisories/GHSA-2c4m-59x9-fr2gghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-29401ghsaADVISORY
- pkg.go.dev/vuln/GO-2023-1737nvdThird Party AdvisoryWEB
- github.com/gin-gonic/gin/releases/tag/v1.9.1nvdRelease NotesWEB
News mentions
0No linked articles in our index yet.