CVE-2023-45283
Insecure parsing of Windows paths with a \??\ prefix in path/filepath
描述
The filepath package does not recognize paths with a \??\ prefix as special. On Windows, a path beginning with \??\ is a Root Local Device path equivalent to a path beginning with \\?\. Paths with a \??\ prefix may be used to access arbitrary locations on the system. For example, the path \??\c:\x is equivalent to the more common path c:\x. Before fix, Clean could convert a rooted path such as \a\..\??\b into the root local device path \??\b. Clean will now convert this to .\??\b. Similarly, Join(\, ??, b) could convert a seemingly innocent sequence of path elements into the root local device path \??\b. Join will now convert this to \.\??\b. In addition, with fix, IsAbs now correctly reports paths beginning with \??\ as absolute, and VolumeName correctly reports the \??\ prefix as a volume name. UPDATE: Go 1.20.11 and Go 1.21.4 inadvertently changed the definition of the volume name in Windows paths starting with \?, resulting in filepath.Clean(\?\c:) returning \?\c: rather than \?\c:\ (among other effects). The previous behavior has been restored.
如何修補 CVE-2023-45283
要修補 CVE-2023-45283,請將受影響套件升級到下列已修補版本。
- —升級至 1.20.11 或更新版本
- —未列出修補版本
- —未列出修補版本
- —升級至 1.20.11 或更新版本
CVE-2023-45283 正在被利用嗎?
低 — EPSS 為 2.8%,目前沒有觀察到大規模利用活動。
受影響套件(4)
- from 0, < 1.20.11, >= 1.21.0-0, < 1.21.4
- from 0
- from 0
- from 0, < 1.20.11, >= 1.21.0-0, < 1.21.4
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |