—
GO-2022-0230
Improper limitation of path name in github.com/containernetworking/cni
Quick fix
GO-2022-0230 — github.com/containernetworking/cni: upgrade to the fixed version with the command below.
go get github.com/containernetworking/cni@v0.8.1Details
The FindInPath function is vulnerable to directory traversal attacks, potentially permitting attackers to execute arbitrary binaries.
This function does not sanitize its plugin parameter, so parameter names containing "../" or other such elements may reference arbitrary locations on the filesystem.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/containernetworking/cni
Introduced in:
0Fixed in: 0.8.1Fix
go get github.com/containernetworking/cni@v0.8.1