GO-2022-1027

    Dashboard / Vulnerabilities / GO-2022-1027

    GO-2022-1027

    Published: 5 Oct 2022Last Modified: 20 May 2024

    Summary: Path traversal in github.com/cloudwego/hertz

    Details: Improper path sanitization on Windows permits path traversal attacks. Static file serving with the Static or StaticFS functions allows an attacker to access files from outside the filesystem root. This vulnerability does not affect non-Windows systems.

    Affected packages

    Package

    Name: github.com/cloudwego/hertz

    Purl: pkg:golang/github.com/cloudwego/hertz

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -0.3.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GO-2022-1027 | CVE-DB