CVE-2022-38638: Path Traversal
Published Sep 9, 2022
·Updated
Casdoor v1.97.3 was discovered to contain an arbitrary file write vulnerability via the fullFilePath parameter at /api/upload-resource.
Affected Software
2 affected componentsFixes available
go/github.com/casdoor/casdoor<1.103.1
1.103.1
Casbin Casdoor=1.97.3
Remediation
Patch Available
Event History
Sep 9, 2022
CVE Published
via MITRE·07:40 PM
Data Sourced
via MITRE·07:40 PM
Description
Sep 10, 2022
Advisory Published
12:00 AM
Frequently Asked Questions
1
What is the severity of CVE-2022-38638?
CVE-2022-38638 is classified as a high severity vulnerability due to its potential for arbitrary file writes.
2
How do I fix CVE-2022-38638?
To fix CVE-2022-38638, upgrade Casdoor to version 1.103.1 or later.
3
What does CVE-2022-38638 affect?
CVE-2022-38638 affects Casdoor version 1.97.3 and earlier installations.
4
What type of vulnerability is CVE-2022-38638?
CVE-2022-38638 is an arbitrary file write vulnerability.
5
Where can I find more information about CVE-2022-38638?
More information about CVE-2022-38638 can typically be found in security advisories or GitHub issue discussions related to Casdoor.