archiver
archiver copied to clipboard
CVE-2024-0406 Archiver Path Traversal vulnerability
https://pkg.go.dev/vuln/GO-2024-2698 was published today and makes https://pkg.go.dev/golang.org/x/vuln/cmd/govulncheck fail.
that's only if using 3.5.1, 3.5.2 is good https://github.com/advisories/GHSA-rhh4-rh7c-7r5v
But 3.5.2 is not released yet, it is only available in a fork
@mholt Any chance to publish a v3.5.2 as fix?
@mholt I am also looking for the fix of this CVE. Any chance we are going to publish v3.5.2 this week?
I'd also like to see a release of this. Our build is failing with govulncheck because of this.
@mholt Just checking in again to know if you plan to release the CVE-free version soon.
@mholt Just rechecking if we will get CVE-free version any time soon?