google-cloud-storage is vulnerable to Path Traversal
65
Medium Risk
Affected versions of this package allow directory downloads to process blob names containing path traversal sequences, which may resolve outside the intended target directory and lead to arbitrary file overwrite. An attacker could exploit this by uploading or referencing a crafted blob with traversal paths, causing the application to write files to sensitive locations on the host filesystem during download operations, potentially enabling data corruption, privilege escalation, or remote code execution depending on the overwritten file.
You are affected if you are using a version that falls within the vulnerable range.
google-cloud-storage is vulnerable to Path Traversal in versions 2.24.0 - 2.62.1.
Upgrade the com.google.cloud:google-cloud-storage library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant