CVE-2022-32190
Summary
| CVE | CVE-2022-32190 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-09-13 18:15:00 UTC |
| Updated | 2023-11-07 03:47:00 UTC |
| Description | JoinPath and URL.JoinPath do not remove ../ path elements appended to a relative path. For example, JoinPath("https://go.dev", "../go") returns the URL "https://go.dev/../go", despite the JoinPath documentation stating that ../ path elements are removed from the result. |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Operating System |
Fedoraproject |
Fedora |
37 |
All |
All |
All |
| Application |
Golang |
Go |
All |
All |
All |
All |
| Application |
Golang |
Go |
1.19.0 |
- |
All |
All |
| Application |
Golang |
Go |
1.19.0 |
beta1 |
All |
All |
| Application |
Golang |
Go |
1.19.0 |
rc1 |
All |
All |
| Application |
Golang |
Go |
1.19.0 |
rc2 |
All |
All |
References
| Reference | Source | Link | Tags |
|---|
| [security] Go 1.19.1 and Go 1.18.6 are released |
CONFIRM |
groups.google.com |
|
| GO-2022-0988 - Go Packages |
CONFIRM |
pkg.go.dev |
|
| net/url: JoinPath doesn't strip relative path components in all circumstances · Issue #54385 · golang/go · GitHub |
CONFIRM |
go.dev |
|
| go.dev/cl/423514 |
CONFIRM |
go.dev |
|
| [SECURITY] Fedora 37 Update: golang-1.19.1-1.fc37 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Mailing List, Third Party Advisory |
| Go: Multiple Vulnerabilities (GLSA 202209-26) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160322 Oracle Enterprise Linux Security Update for ol8addon (ELSA-2022-24267)
- 160499 Oracle Enterprise Linux Security Update for ol8addon (ELSA-2023-18908)
- 184567 Debian Security Update for golang-1.19 (CVE-2022-32190)
- 241747 Red Hat OpenShift Container Platform 4.12 Security Update (RHSA-2023:3613)
- 283108 Fedora Security Update for golang (FEDORA-2022-67ec8c61d0)
- 354500 Amazon Linux Security Advisory for golang : ALAS2022-2022-144
- 354527 Amazon Linux Security Advisory for golang : ALAS2022-2022-193
- 354566 Amazon Linux Security Advisory for golang : ALAS-2022-193
- 355212 Amazon Linux Security Advisory for golang : ALAS2023-2023-048
- 502503 Alpine Linux Security Update for go
- 502858 Alpine Linux Security Update for go
- 690935 Free Berkeley Software Distribution (FreeBSD) Security Update for go (6fea7103-2ea4-11ed-b403-3dae8ac60d3e)
- 710627 Gentoo Linux Go Multiple Vulnerabilities (GLSA 202209-26)
- 753397 SUSE Enterprise Linux Security Update for go1.19 (SUSE-SU-2022:3326-1)
- 770197 Red Hat OpenShift Container Platform 4.12 Security Update (RHSA-2023:3613)