7.5

CVE-2022-32190

Failure to strip relative path components in net/url

JoinPath and URL.JoinPath do not remove ../ path elements appended to a relative path. For example, JoinPath("https://go.dev", "../go") returns the URL "https://go.dev/../go", despite the JoinPath documentation stating that ../ path elements are removed from the result.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Golang ≫ Go Version 1.19.0 Update -
Golang ≫ Go Version 1.19.0 Update beta1
Golang ≫ Go Version 1.19.0 Update rc1
Golang ≫ Go Version 1.19.0 Update rc2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.79% 0.766
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

https://groups.google.com/g/golang-announce/c/x49AQzIVX-s
Third Party Advisory
Mailing List
https://go.dev/cl/423514
Patch
Release Notes
https://go.dev/issue/54385
Patch
Vendor Advisory
Issue Tracking
https://pkg.go.dev/vuln/GO-2022-0988
Patch
Vendor Advisory
Issue Tracking