Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:36568
HistoryAug 02, 2022 - 2:28 p.m.

Path Traversal

2022-08-0214:28:27
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
41
path traversal
minio
vulnerability
downloadreleaseurl
update.go
admin:serviceupdate
file system

EPSS

0.004

Percentile

72.7%

github.com/minio/minio is vulnerable to path traversal. The vulnerability exists in downloadReleaseURL function in update.go because the admin:ServiceUpdate is not properly handled which allows an attacker to get access to the file system.