Path traversal in Go programming language - CVE-2022-29804

 

Path traversal in Go programming language - CVE-2022-29804

Published: March 21, 2023


Vulnerability identifier: #VU73872
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-29804
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error within the filepath.Clean function on Windows, which can convert certain invalid paths to valid, absolute paths, potentially allowing a directory traversal attack. A remote attacker can pass specially crafted data to the application and perform directory traversal attacks.


Affected software

Go programming language
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Enterprise Storage
Oracle Solaris
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Development Tools
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
Development Tools Module
openSUSE Leap
openEuler
Astronomer with IBM
ObjectScale
IBM Cloud Pak System
Splunk Enterprise
golang
golang-help
golang-devel
go1.17-race
go1.17-doc
go1.17
go1.18-race
go1.18-doc
go1.18
go1.18-openssl-race
go1.18-openssl
go1.18-openssl-doc
IBM Cloud Pak for Multicloud Management Security Services
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Spectrum Protect Plus
Cloud Pak for Data

How to mitigate CVE-2022-29804

Install update from vendor's website.

Go programming language - addressed in versions 1.17.11, 1.18.3
Astronomer with IBM - update to 1.0.1
IBM Cloud Pak System - update to 2.3.3.6
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
ObjectScale - update to 1.4.0
golang - update to 1.15.7-16
golang-help - update to 1.15.7-16
golang-devel - update to 1.15.7-16
go1.17-race - update to 1.17.11-150000.1.37.1
go1.17-doc - update to 1.17.11-150000.1.37.1
go1.17 - update to 1.17.11-150000.1.37.1
go1.18-race - update to 1.18.3-150000.1.20.1
go1.18-doc - update to 1.18.3-150000.1.20.1
go1.18 - update to 1.18.3-150000.1.20.1
go1.18-openssl-race - update to 1.18.10.1-150000.1.9.1
go1.18-openssl - update to 1.18.10.1-150000.1.9.1
go1.18-openssl-doc - update to 1.18.10.1-150000.1.9.1
IBM Cloud Pak for Multicloud Management Security Services - update to 2.3 Fix Pack 6
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.5.3
Cloud Pak for Data - update to 4.8.5
IBM Spectrum Protect Plus - update to 10.1.12

External References

Related Security Bulletins