Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2022-29804

Published: August 10, 2022Last modified: November 8, 2023

Description

Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and Go 1.18.3 on Windows allows potential directory traversal attack.

Severity score breakdown

ParameterValue
Base score7.5
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactNONE
Availability impactNONE
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSgoNot affected (1.19.9-r1)
StreamgoNot affected (1.21.0-r2)

References

ON THIS PAGE