CVE-2022-29804
10.08.2022, 20:15
Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and Go 1.18.3 on Windows allows potential directory traversal attack.
Vendor | Product | Version |
---|---|---|
golang | go | 𝑥 < 1.17.11 |
golang | go | 1.18.0 ≤ 𝑥 < 1.18.3 |
𝑥
= Vulnerable software versions

Ubuntu Releases
References