CVE-2022-29804

Publication date 10 August 2022

Last updated 24 July 2024


Ubuntu priority

Cvss 3 Severity Score

7.5 · High

Score breakdown

Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and Go 1.18.3 on Windows allows potential directory traversal attack.

Status

Package Ubuntu Release Status
golang-1.15 21.10 impish Ignored end of life
golang-1.17 23.04 lunar Not in release
22.10 kinetic Not in release
22.04 LTS jammy
Not affected
21.10 impish
Not affected
golang-1.18 23.04 lunar Not in release
22.10 kinetic Not in release
22.04 LTS jammy
Not affected
20.04 LTS focal
Not affected
18.04 LTS bionic
Not affected
golang-1.8 18.04 LTS bionic
Not affected

Severity score breakdown

Parameter Value
Base score 7.5 · High
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Scope Unchanged
Confidentiality High
Integrity impact None
Availability impact None
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N