This affects all versions of package github.com/kataras/iris; all versions of package github.com/kataras/iris/v12. The unsafe handling of file names during upload using UploadFormFiles method may enable attackers to write to arbitrary locations outside the designated target folder. References: https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMKATARASIRIS-2325169 https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMKATARASIRISV12-2325170 Upstream patch: https://github.com/kataras/iris/commit/e213dba0d32ff66653e0ef124bc5088817264b08
The following services are using iris-v12 as stated the version v12 is affected and a patch published