[GO-2022-0988] Failure to strip relative path components in net/url

Severity High
Affected Packages 1
Fixed Packages 1
CVEs 1

JoinPath and URL.JoinPath do not remove ../ path elements appended to a relative
path. For example, JoinPath("https://go.dev", "../go") returns the URL
"https://go.dev/../go", despite the JoinPath documentation stating that ../ path
elements are removed from the result.

Package Affected Version
pkg:golang/net/url >= 1.19.0, < 1.19.1
Package Fixed Version
pkg:golang/net/url = 1.19.1
ID
GO-2022-0988
Severity
high
Severity from
CVE-2022-32190
URL
https://pkg.go.dev/vuln/GO-2022-0988
Published
2022-09-12T18:33:21
(2 years ago)
Modified
2024-07-17T19:54:18
(2 months ago)
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Fixed pkg:golang/net/url net url = 1.19.1
Affected pkg:golang/net/url net url >= 1.19.0 < 1.19.1
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...