CVE Database
/

CVE-2022-41722

Back to search

CVE-2022-41722

Published: Feb 28, 2023

Modified: Mar 7, 2025

PUBLISHED

Description

A path traversal vulnerability exists in filepath.Clean on Windows. On Windows, the filepath.Clean function could transform an invalid path such as "a/../c:/b" into the valid path "c:\b". This transformation of a relative (if invalid) path into an absolute path could enable a directory traversal attack. After fix, the filepath.Clean function transforms this path into the relative (but still invalid) path ".\c:\b".

VendorProductVersions

Go standard library

path/filepath

affected
0 - < 1.19.6
affected
1.20.0-0 - < 1.20.1

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now