CVE-2022-41722
Summary
| CVE | CVE-2022-41722 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-02-28 18:15:00 UTC |
| Updated | 2023-11-07 03:52:00 UTC |
| Description | A path traversal vulnerability exists in filepath.Clean on Windows. On Windows, the filepath.Clean function could transform an invalid path such as "a/../c:/b" into the valid path "c:\b". This transformation of a relative (if invalid) path into an absolute path could enable a directory traversal attack. After fix, the filepath.Clean function transforms this path into the relative (but still invalid) path ".\c:\b". |
Risk And Classification
Problem Types: CWE-22
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| go.dev/cl/468123 | MISC | go.dev | |
| GO-2023-1568 - Go Packages | MISC | pkg.go.dev | |
| path/filepath: path traversal in filepath.Clean on Windows (CVE-2022-41722) · Issue #57274 · golang/go · GitHub | MISC | go.dev | |
| [security] Go 1.20.1 and Go 1.19.6 are released | MISC | groups.google.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 183983 Debian Security Update for golang-1.19 (CVE-2022-41722)
- 241623 Red Hat OpenShift Container Platform 4.13 Security Update (RHSA-2023:3366)
- 354890 Amazon Linux Security Advisory for golang : ALAS2-2023-2015
- 354901 Amazon Linux Security Advisory for golang : ALAS-2023-1731
- 355216 Amazon Linux Security Advisory for golang : ALAS2023-2023-175
- 356304 Amazon Linux Security Advisory for golang : ALASGOLANG1.19-2023-002
- 378883 Splunk Enterprise August Third Party Package Updates (SVD-2023-0808)
- 691061 Free Berkeley Software Distribution (FreeBSD) Security Update for go (3d73e384-ad1f-11ed-983c-83fe35862e3a)
- 753772 SUSE Enterprise Linux Security Update for go1.19 (SUSE-SU-2023:0733-1)
- 770189 Red Hat OpenShift Container Platform 4.13 Security Update (RHSA-2023:3366)
- 905636 Common Base Linux Mariner (CBL-Mariner) Security Update for golang (13720)
- 905641 Common Base Linux Mariner (CBL-Mariner) Security Update for msft-golang (13738)
- 905642 Common Base Linux Mariner (CBL-Mariner) Security Update for golang (13730)
- 906771 Common Base Linux Mariner (CBL-Mariner) Security Update for msft-golang (13738-1)
- 907782 Common Base Linux Mariner (CBL-Mariner) Security Update for golang (13720-1)
- 907791 Common Base Linux Mariner (CBL-Mariner) Security Update for golang (13730-1)