CVE-2022-29804
EUVD-2022-3412510.08.2022, 20:15
Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and Go 1.18.3 on Windows allows potential directory traversal attack.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| golang | go | 𝑥 < 1.17.11 |
| golang | go | 1.18.0 ≤ 𝑥 < 1.18.3 |
𝑥
= Vulnerable software versions
Ubuntu Releases
References