File tree 1 file changed +27
-0
lines changed
1 file changed +27
-0
lines changed Original file line number Diff line number Diff line change
1
+ modules :
2
+ - module : github.com/beego/beego
3
+ versions :
4
+ - fixed : 1.12.11
5
+ packages :
6
+ - package : github.com/beego/beego
7
+ symbols :
8
+ - Tree.Match
9
+ - module : github.com/beego/beego/v2
10
+ versions :
11
+ - introduced : 2.0.0
12
+ fixed : 2.0.4
13
+ vulnerable_at : 2.0.3
14
+ packages :
15
+ - package : github.com/beego/beego/v2/server/web
16
+ symbols :
17
+ - Tree.Match
18
+ description : |
19
+ The leafInfo.match() function uses path.join()
20
+ to deal with wildcard values which can lead to cross directory risk.
21
+ cves :
22
+ - CVE-2022-31836
23
+ ghsas :
24
+ - GHSA-95f9-94vc-665h
25
+ links :
26
+ pr : https://github.com/beego/beego/pull/5025
27
+ commit : https://github.com/beego/beego/pull/5025/commits/ea5ae58d40589d249cf577a053e490509de2bf57
You can’t perform that action at this time.
0 commit comments