CRITICAL 9.8 Go
Path Traversal in Beego
GHSA-95f9-94vc-665h · CVE-2022-31836 · GO-2022-0569
Published · Modified
Description
The leafInfo.match() function in Beego v2.0.3 and below uses path.join() to deal with wildcardvalues which can lead to cross directory risk.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2022-31836
- WEB https://github.com/beego/beego/issues/4961
- WEB https://github.com/beego/beego/pull/5025
- WEB https://github.com/beego/beego/pull/5025/commits/ea5ae58d40589d249cf577a053e490509de2bf57
- ADVISORY https://github.com/advisories/GHSA-95f9-94vc-665h
- PACKAGE https://github.com/beego/beego
- WEB https://pkg.go.dev/vuln/GO-2022-0569
Ready to move
Start Securing
Free, no credit card | First findings in minutes