CVE-2022-29804: Path traversal via Clean on Windows in path/filepath
Golang Go could allow a local attacker to bypass security restrictions, caused by a flaw in the filepath.Clean function. By sending a specially-crafted request, an attacker could exploit this vulnerability to convert an invalid path to a valid, absolute path.
Other sources
Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and Go 1.18.3 on Windows allows potential directory traversal attack.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-29804?
CVE-2022-29804 is a vulnerability that allows potential directory traversal attack by converting certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and Go 1.18.3 on Windows.
How severe is CVE-2022-29804?
CVE-2022-29804 has a severity value of 7.5 (High).
Which software versions are affected by CVE-2022-29804?
CVE-2022-29804 affects Go 1.17.11 and Go 1.18.0 to 1.18.3 on Windows.
How can I fix CVE-2022-29804?
To fix CVE-2022-29804, update to Go 1.17.11 or Go 1.18.3 or later.
Is Microsoft Windows vulnerable to CVE-2022-29804?
No, Microsoft Windows is not vulnerable to CVE-2022-29804.