CVE-2022-31836

CRITICAL9.8EPSS 0.45%

Path Traversal in Beego

Published: 7/6/2022Modified: 3/13/2026
Also known as:GHSA-95f9-94vc-665hGO-2022-0569

Description

The `leafInfo.match()` function in Beego v2.0.3 and below uses `path.join()` to deal with wildcardvalues which can lead to cross directory risk.

Affected packages (5)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References (7)