Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-32190

Опубликовано: 13 сент. 2022
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

JoinPath and URL.JoinPath do not remove ../ path elements appended to a relative path. For example, JoinPath("https://go.dev", "../go") returns the URL "https://go.dev/../go", despite the JoinPath documentation stating that ../ path elements are removed from the result.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:golang:go:1.19.0:-:*:*:*:*:*:*
cpe:2.3:a:golang:go:1.19.0:beta1:*:*:*:*:*:*
cpe:2.3:a:golang:go:1.19.0:rc1:*:*:*:*:*:*
cpe:2.3:a:golang:go:1.19.0:rc2:*:*:*:*:*:*

EPSS

Процентиль: 24%
0.00076
Низкий

7.5 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 3 года назад

JoinPath and URL.JoinPath do not remove ../ path elements appended to a relative path. For example, JoinPath("https://go.dev", "../go") returns the URL "https://go.dev/../go", despite the JoinPath documentation stating that ../ path elements are removed from the result.

CVSS3: 7.5
redhat
почти 3 года назад

JoinPath and URL.JoinPath do not remove ../ path elements appended to a relative path. For example, JoinPath("https://go.dev", "../go") returns the URL "https://go.dev/../go", despite the JoinPath documentation stating that ../ path elements are removed from the result.

CVSS3: 7.5
debian
почти 3 года назад

JoinPath and URL.JoinPath do not remove ../ path elements appended to ...

CVSS3: 9.8
github
почти 3 года назад

JoinPath and URL.JoinPath do not remove ../ path elements appended to a relative path. For example, JoinPath("https://go.dev", "../go") returns the URL "https://go.dev/../go", despite the JoinPath documentation stating that ../ path elements are removed from the result.

suse-cvrf
больше 2 лет назад

Security update for go1.19

EPSS

Процентиль: 24%
0.00076
Низкий

7.5 High

CVSS3

Дефекты

CWE-22