[GO-2022-0988] Failure to strip relative path components in net/url
Severity
High
Affected Packages
1
Fixed Packages
1
CVEs
1
JoinPath and URL.JoinPath do not remove ../ path elements appended to a relative
path. For example, JoinPath("https://go.dev", "../go") returns the URL
"https://go.dev/../go", despite the JoinPath documentation stating that ../ path
elements are removed from the result.
Package | Affected Version |
---|---|
pkg:golang/net/url | >= 1.19.0, < 1.19.1 |
Package | Fixed Version |
---|---|
pkg:golang/net/url | = 1.19.1 |
- ID
- GO-2022-0988
- Severity
- high
- Severity from
- CVE-2022-32190
- URL
- https://pkg.go.dev/vuln/GO-2022-0988
- Published
-
2022-09-12T18:33:21
(2 years ago) - Modified
-
2024-07-17T19:54:18
(2 months ago) - Other Advisories
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |