Lucene search

K
osvGoogleOSV:CVE-2022-21221
HistoryMar 17, 2022 - 12:15 p.m.

CVE-2022-21221

2022-03-1712:15:08
Google
osv.dev
8
github.com/valyala/fasthttp
directory traversal
servefile function
improper sanitization
windows users

AI Score

6.7

Confidence

High

EPSS

0.002

Percentile

61.6%

The package github.com/valyala/fasthttp before 1.34.0 are vulnerable to Directory Traversal via the ServeFile function, due to improper sanitization. It is possible to be exploited by using a backslash %5c character in the path. Note: This security issue impacts Windows users only.

AI Score

6.7

Confidence

High

EPSS

0.002

Percentile

61.6%