Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and Go 1.18.3 on Windows allows potential directory traversal attack.
2022-08-10T20:15:34.890
2024-11-21T06:59:42.800
Modified
CVSSv3.1: 7.5 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | golang | go | < 1.17.11 | Yes |
| Application | golang | go | < 1.18.3 | Yes |
| Operating System | microsoft | windows | - | No |