We found results for “”
WS-2021-0194
Good to know:
Date: April 14, 2021
Goa in versions v1.0.0 to v1.4.2 is allowing for directory traversal, an attacker to read files outside of the target directory that the server has permission to read. related to service.go
Language: Go
Severity Score
Severity Score
Weakness Type (CWE)
Path Traversal: '.../...//'
CWE-35Top Fix
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | NONE |
Availability (A): | NONE |