Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38363
HistoryDec 08, 2022 - 2:28 a.m.

Path Traversal

2022-12-0802:28:44
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11
path traversal
vulnerability
golang/go
os.dirfs
http.dir
windows

0.002 Low

EPSS

Percentile

53.4%

github.com/golang/go is vulnerable to path traversal. The vulnerability exists because the library does not properly escape file paths from the os.DirFS function and http.Dir type on windows, allowing an attacker to access any path on the system via a maliciously crafted path.