VDB
Sign up
—

GO-2022-1027

Path traversal in github.com/cloudwego/hertz

Quick fix

GO-2022-1027 — github.com/cloudwego/hertz: upgrade to the fixed version with the command below.

go get github.com/cloudwego/hertz@v0.3.1

Details

Improper path sanitization on Windows permits path traversal attacks. Static file serving with the Static or StaticFS functions allows an attacker to access files from outside the filesystem root.

This vulnerability does not affect non-Windows systems.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/cloudwego/hertz
Introduced in: 0Fixed in: 0.3.1
Fixgo get github.com/cloudwego/hertz@v0.3.1

References