ZeroHour

CVE-2022-31836

PoC
CVSS 3.1
9.8 critical
EPSS
2%p75
Published
()
Modified
Description

The leafInfo.match() function in Beego v2.0.3 and below uses path.join() to deal with wildcardvalues which can lead to cross directory risk.

Vendors
beego
Products
beego
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.