« Volver al listado

CVE-2022-29804

Estado: ModificadaAlta (7.5)—

Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and Go 1.18.3 on Windows allows potential directory traversal attack.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-29804",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@golang.org",
      "affectedData": [
        {
          "vendor": "Go standard library",
          "product": "path/filepath",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "1.17.11",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "1.18.0-0",
              "lessThan": "1.18.3",
              "versionType": "semver"
            }
          ],
          "platforms": [
            "windows"
          ],
          "packageName": "path/filepath",
          "collectionURL": "https://pkg.go.dev",
          "defaultStatus": "unaffected",
          "programRoutines": [
            {
              "name": "Clean"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-08-10T20:15:34.890",
  "references": [
    {
      "url": "https://go.dev/cl/401595",
      "source": "security@golang.org"
    },
    {
      "url": "https://go.dev/issue/52476",
      "source": "security@golang.org"
    },
    {
      "url": "https://go.googlesource.com/go/+/9cd1818a7d019c02fa4898b3e45a323e35033290",
      "source": "security@golang.org"
    },
    {
      "url": "https://groups.google.com/g/golang-announce/c/TzIC9-t8Ytg/m/IWz5T6x7AAAJ",
      "source": "security@golang.org"
    },
    {
      "url": "https://pkg.go.dev/vuln/GO-2022-0533",
      "source": "security@golang.org"
    },
    {
      "url": "https://go.dev/cl/401595",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://go.dev/issue/52476",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://go.googlesource.com/go/+/9cd1818a7d019c02fa4898b3e45a323e35033290",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://groups.google.com/g/golang-announce/c/TzIC9-t8Ytg/m/IWz5T6x7AAAJ",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://pkg.go.dev/vuln/GO-2022-0533",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and Go 1.18.3 on Windows allows potential directory traversal attack."
    },
    {
      "lang": "es",
      "value": "En filepath.Clean en path/filepath en Go versiones anteriores a 1.17.11 y en 1.18.x antes de 1.18.3 en Windows, las rutas inválidas como .\\c: podían convertirse en rutas válidas (como c: en este ejemplo)."
    }
  ],
  "lastModified": "2026-06-17T04:40:44.503",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "338E9C2D-AE40-4FA3-9A44-08C9B508B756",
              "versionEndExcluding": "1.17.11"
            },
            {
              "criteria": "cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6782EAAE-0437-495C-A6B4-1CFB39DAAFA6",
              "versionEndExcluding": "1.18.3",
              "versionStartIncluding": "1.18.0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "security@golang.org"
}