Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v9vr-w93g-qph7

Опубликовано: 06 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

The filepath.Walk and filepath.WalkDir functions are documented as not following symbolic links, but both functions are susceptible to a TOCTOU (time of check/time of use) race condition where a portion of the path being walked is replaced with a symbolic link while the walk is in progress.

The filepath.Walk and filepath.WalkDir functions are documented as not following symbolic links, but both functions are susceptible to a TOCTOU (time of check/time of use) race condition where a portion of the path being walked is replaced with a symbolic link while the walk is in progress.

EPSS

Процентиль: 12%
0.00039
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 3.7
ubuntu
5 месяцев назад

The filepath.Walk and filepath.WalkDir functions are documented as not following symbolic links, but both functions are susceptible to a TOCTOU (time of check/time of use) race condition where a portion of the path being walked is replaced with a symbolic link while the walk is in progress.

CVSS3: 5.6
redhat
5 месяцев назад

The filepath.Walk and filepath.WalkDir functions are documented as not following symbolic links, but both functions are susceptible to a TOCTOU (time of check/time of use) race condition where a portion of the path being walked is replaced with a symbolic link while the walk is in progress.

CVSS3: 3.7
nvd
5 месяцев назад

The filepath.Walk and filepath.WalkDir functions are documented as not following symbolic links, but both functions are susceptible to a TOCTOU (time of check/time of use) race condition where a portion of the path being walked is replaced with a symbolic link while the walk is in progress.

CVSS3: 3.7
debian
5 месяцев назад

The filepath.Walk and filepath.WalkDir functions are documented as not ...

EPSS

Процентиль: 12%
0.00039
Низкий

6.5 Medium

CVSS3