Back

HIGH

Path traversal on Windows in path/filepath

Published Feb 28, 2023

Description

A path traversal vulnerability exists in filepath.Clean on Windows. On Windows, the filepath.Clean function could transform an invalid path such as "a/../c:/b" into the valid path "c:\b". This transformation of a relative (if invalid) path into an absolute path could enable a directory traversal attack. After fix, the filepath.Clean function transforms this path into the relative (but still invalid) path ".\c:\b".

Affected products

Remediation

Red Hat statement

This CVE is specific to versions of Go on Windows. It does not affect any packages shipped with Red Hat Enterprise Linux 8 and Red Hat Enterprise Linux 9. The following components were fixed in RHSA-2023:3366 and have therefore been marked as "Not Affected": `openshift`, `cri-tools`, `cri-o`, `containernetworking-plugins` and `conmon`

Weaknesses (1)

References (9)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner Go
Published Feb 28, 2023
Updated Mar 7, 2025
Reserved Sep 28, 2022

CISA Vulnrichment

Updated Mar 7, 2025

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Feb 15, 2023
Bugzilla 2203008

ENISA EUVD

Assigner Go
Published Feb 28, 2023
Updated Mar 7, 2025

GitHub

No data