VDB
Sign up
HIGH8.8

GHSA-wr3p-r5fj-wf97

Beego privilege escalation vulnerability

Quick fix

GHSA-wr3p-r5fj-wf97 — github.com/beego/beego/v2: upgrade to the fixed version with the command below.

go get github.com/beego/beego/v2@v2.2.1

Details

An issue in beego v.2.2.0 and before allows a remote attacker to escalate privileges via the `getCacheFileName` function in the `file.go` file.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/beego/beego/v2
Introduced in: 0Fixed in: 2.2.1
Fixgo get github.com/beego/beego/v2@v2.2.1

References