CVE-2022-29804Path Traversal in Standard Library Path Filepath

Severity
7.5HIGHNVD
EPSS
0.1%
top 84.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 10
Latest updateApr 8

Description

Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and Go 1.18.3 on Windows allows potential directory traversal attack.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

CVEListV5go_standard_library/path_filepath1.18.0-01.18.3+1
NVDgolang/go1.18.01.18.3+1

🔴Vulnerability Details

3
GHSA
GHSA-4r7w-gv7f-q74g: Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 12022-08-11
CVEList
Path traversal via Clean on Windows in path/filepath2022-08-09
OSV
Path traversal via Clean on Windows in path/filepath2022-07-28

📋Vendor Advisories

3
Microsoft
Visual Studio Elevation of Privilege Vulnerability2025-04-08
Microsoft
Path traversal via Clean on Windows in path/filepath2022-08-09
Debian
CVE-2022-29804: golang-1.15 - Incorrect conversion of certain invalid paths to valid, absolute paths in Clean ...2022
CVE-2022-29804 — Path Traversal | cvebase