Skip to content

Commit 0485df8

Browse files
committed
x/vulndb: add data/reports/GO-2022-0569.yaml for CVE-2022-31836
Fixes #569 Change-Id: I63cd4ae85d19c56bfa64d567f362b2031497a8e1 Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/425084 Run-TryBot: Jonathan Amsterdam <[email protected]> TryBot-Result: Gopher Robot <[email protected]> Reviewed-by: Julie Qiu <[email protected]>
1 parent 4c21b17 commit 0485df8

File tree

1 file changed

+27
-0
lines changed

1 file changed

+27
-0
lines changed

data/reports/GO-2022-0569.yaml

Lines changed: 27 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,27 @@
1+
modules:
2+
- module: github.com/beego/beego
3+
versions:
4+
- fixed: 1.12.11
5+
packages:
6+
- package: github.com/beego/beego
7+
symbols:
8+
- Tree.Match
9+
- module: github.com/beego/beego/v2
10+
versions:
11+
- introduced: 2.0.0
12+
fixed: 2.0.4
13+
vulnerable_at: 2.0.3
14+
packages:
15+
- package: github.com/beego/beego/v2/server/web
16+
symbols:
17+
- Tree.Match
18+
description: |
19+
The leafInfo.match() function uses path.join()
20+
to deal with wildcard values which can lead to cross directory risk.
21+
cves:
22+
- CVE-2022-31836
23+
ghsas:
24+
- GHSA-95f9-94vc-665h
25+
links:
26+
pr: https://github.com/beego/beego/pull/5025
27+
commit: https://github.com/beego/beego/pull/5025/commits/ea5ae58d40589d249cf577a053e490509de2bf57

0 commit comments

Comments
 (0)