Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-22873

Опубликовано: 04 фев. 2026
Источник: ubuntu
Приоритет: medium
CVSS3: 3.8

Описание

It was possible to improperly access the parent directory of an os.Root by opening a filename ending in "../". For example, Root.Open("../") would open the parent directory of the Root. This escape only permits opening the parent directory itself, not ancestors of the parent or files contained within the parent.

РелизСтатусПримечание
devel

not-affected

Vulnerable code only present in 1.24.x releases
esm-apps/jammy

not-affected

Vulnerable code only present in 1.24.x releases
esm-apps/noble

not-affected

Vulnerable code only present in 1.24.x releases
esm-apps/resolute

not-affected

Vulnerable code only present in 1.24.x releases
esm-infra/focal

DNE

focal

DNE

jammy

not-affected

Vulnerable code only present in 1.24.x releases
noble

not-affected

Vulnerable code only present in 1.24.x releases
oracular

not-affected

Vulnerable code only present in 1.24.x releases
plucky

not-affected

Vulnerable code only present in 1.24.x releases

Показывать по

РелизСтатусПримечание
devel

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

needs-triage

esm-infra/focal

DNE

focal

DNE

jammy

needs-triage

noble

needs-triage

oracular

DNE

plucky

ignored

end of life, was needs-triage
questing

ignored

end of life, was needs-triage

Показывать по

3.8 Low

CVSS3

Связанные уязвимости

CVSS3: 5.3
redhat
6 месяцев назад

It was possible to improperly access the parent directory of an os.Root by opening a filename ending in "../". For example, Root.Open("../") would open the parent directory of the Root. This escape only permits opening the parent directory itself, not ancestors of the parent or files contained within the parent.

CVSS3: 3.8
nvd
6 месяцев назад

It was possible to improperly access the parent directory of an os.Root by opening a filename ending in "../". For example, Root.Open("../") would open the parent directory of the Root. This escape only permits opening the parent directory itself, not ancestors of the parent or files contained within the parent.

CVSS3: 3.8
debian
6 месяцев назад

It was possible to improperly access the parent directory of an os.Roo ...

suse-cvrf
около 1 года назад

Security update for go1.24

suse-cvrf
около 1 года назад

Security update for go1.24

3.8 Low

CVSS3