CVE-2022-41722
Published: Feb 28, 2023
Modified: Mar 7, 2025
Description
A path traversal vulnerability exists in filepath.Clean on Windows. On Windows, the filepath.Clean function could transform an invalid path such as "a/../c:/b" into the valid path "c:\b". This transformation of a relative (if invalid) path into an absolute path could enable a directory traversal attack. After fix, the filepath.Clean function transforms this path into the relative (but still invalid) path ".\c:\b".
| Vendor | Product | Versions |
|---|---|---|
Go standard library | path/filepath | affected 0 - < 1.19.6affected 1.20.0-0 - < 1.20.1 |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now