CVE-2022-29804: Path traversal via Clean on Windows in path/filepath
Golang Go could allow a local attacker to bypass security restrictions, caused by a flaw in the filepath.Clean function. By sending a specially-crafted request, an attacker could exploit this vulnerability to convert an invalid path to a valid, absolute path.
Other sources
Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and Go 1.18.3 on Windows allows potential directory traversal attack.
— MITRE
Path traversal via Clean on Windows in path/filepath
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Golang Goto a version that resolves this vulnerability.Fixed in 1.17.11 - Upgrade
Upgrade
Golang Goto a version that resolves this vulnerability.Fixed in 1.18.3 - Compensating control
As a compensating control on Windows, ensure any application-level security checks are performed on the original, uncleaned path (or via an allowlist of permitted paths), since filepath.Clean can incorrectly convert certain invalid paths to valid, absolute paths in Go versions before 1.17.11 and 1.18.3.
Event History
Frequently Asked Questions
What is CVE-2022-29804?
CVE-2022-29804 is a vulnerability that allows potential directory traversal attack by converting certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and Go 1.18.3 on Windows.
How severe is CVE-2022-29804?
CVE-2022-29804 has a severity value of 7.5 (High).
Which software versions are affected by CVE-2022-29804?
CVE-2022-29804 affects Go 1.17.11 and Go 1.18.0 to 1.18.3 on Windows.
How can I fix CVE-2022-29804?
To fix CVE-2022-29804, update to Go 1.17.11 or Go 1.18.3 or later.
Is Microsoft Windows vulnerable to CVE-2022-29804?
No, Microsoft Windows is not vulnerable to CVE-2022-29804.