—
GO-2022-1027
Path traversal in github.com/cloudwego/hertz
Quick fix
GO-2022-1027 — github.com/cloudwego/hertz: upgrade to the fixed version with the command below.
go get github.com/cloudwego/hertz@v0.3.1Details
Improper path sanitization on Windows permits path traversal attacks. Static file serving with the Static or StaticFS functions allows an attacker to access files from outside the filesystem root.
This vulnerability does not affect non-Windows systems.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/cloudwego/hertz
Introduced in:
0Fixed in: 0.3.1Fix
go get github.com/cloudwego/hertz@v0.3.1