CVE-2022-29804 PUBLISHED

Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and Go 1.18.3 on Windows allows potential directory traversal attack.

EPSS 0.05% · 15.4th percentile

Risk Scores

EPSS Score
0.05%
15.4th percentile

Affected Products

VendorProductVersions
Bitnamigolang0, 1.18.0
Bitnamigolang0, 1.18.0

Timeline

References

Open in Interactive Console →