CVE-2022-32190

JoinPath and URL.JoinPath do not remove ../ path elements appended to a relative path. For example, JoinPath("https://go.dev", "../go") returns the URL "https://go.dev/../go", despite the JoinPath documentation stating that ../ path elements are removed from the result.
References
Link Resource
https://go.dev/cl/423514 Patch Release Notes
https://go.dev/issue/54385 Issue Tracking Patch Vendor Advisory
https://groups.google.com/g/golang-announce/c/x49AQzIVX-s Mailing List Third Party Advisory
https://pkg.go.dev/vuln/GO-2022-0988 Issue Tracking Patch Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:golang:go:1.19.0:-:*:*:*:*:*:*
cpe:2.3:a:golang:go:1.19.0:beta1:*:*:*:*:*:*
cpe:2.3:a:golang:go:1.19.0:rc1:*:*:*:*:*:*
cpe:2.3:a:golang:go:1.19.0:rc2:*:*:*:*:*:*

History

25 Sep 2023, 02:29

Type Values Removed Values Added
CPE cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*

03 Mar 2023, 15:40

Type Values Removed Values Added
References (CONFIRM) https://groups.google.com/g/golang-announce/c/x49AQzIVX-s - Issue Tracking, Mailing List, Third Party Advisory (CONFIRM) https://groups.google.com/g/golang-announce/c/x49AQzIVX-s - Mailing List, Third Party Advisory
CPE cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*

27 Dec 2022, 22:15

Type Values Removed Values Added
References
  • {'url': 'https://security.gentoo.org/glsa/202209-26', 'name': 'GLSA-202209-26', 'tags': ['Third Party Advisory'], 'refsource': 'GENTOO'}
  • {'url': 'https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JXKTHIGE5F576MAPFYCIJXNRGBSPISUF/', 'name': 'FEDORA-2022-45097317b4', 'tags': ['Mailing List', 'Third Party Advisory'], 'refsource': 'FEDORA'}

15 Nov 2022, 18:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 7.5
References (GENTOO) https://security.gentoo.org/glsa/202209-26 - (GENTOO) https://security.gentoo.org/glsa/202209-26 - Third Party Advisory
CPE cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*

29 Sep 2022, 17:15

Type Values Removed Values Added
References
  • (GENTOO) https://security.gentoo.org/glsa/202209-26 -

16 Sep 2022, 02:38

Type Values Removed Values Added
References
  • (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JXKTHIGE5F576MAPFYCIJXNRGBSPISUF/ - Mailing List, Third Party Advisory
References (CONFIRM) https://go.dev/issue/54385 - (CONFIRM) https://go.dev/issue/54385 - Issue Tracking, Patch, Vendor Advisory
References (CONFIRM) https://groups.google.com/g/golang-announce/c/x49AQzIVX-s - (CONFIRM) https://groups.google.com/g/golang-announce/c/x49AQzIVX-s - Issue Tracking, Mailing List, Third Party Advisory
References (CONFIRM) https://pkg.go.dev/vuln/GO-2022-0988 - (CONFIRM) https://pkg.go.dev/vuln/GO-2022-0988 - Issue Tracking, Patch, Vendor Advisory
References (CONFIRM) https://go.dev/cl/423514 - (CONFIRM) https://go.dev/cl/423514 - Patch, Release Notes, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
First Time Golang go
Golang
Fedoraproject
Fedoraproject fedora
CPE cpe:2.3:a:golang:go:1.19.0:rc2:*:*:*:*:*:*
cpe:2.3:a:golang:go:1.19.0:rc1:*:*:*:*:*:*
cpe:2.3:a:golang:go:1.19.0:beta1:*:*:*:*:*:*
cpe:2.3:a:golang:go:1.19.0:-:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
CWE CWE-22

13 Sep 2022, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-09-13 18:15

Updated : 2023-12-10 14:35


NVD link : CVE-2022-32190

Mitre link : CVE-2022-32190

CVE.ORG link : CVE-2022-32190


JSON object : View

Products Affected

golang

  • go
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')