HIGH
An issue in beego v.2.2.0 and before allows a remote attacker to escalate privileges via the getCacheFileName function in file.go file
Published Jul 31, 2024
8.7
HIGHCVSS 4.0
EPSS 0.43%
Description
An issue in beego v.2.2.0 and before allows a remote attacker to escalate privileges via the getCacheFileName function in file.go file
Affected products
No data.
-
Affected
- ≥ 0, ≤ 2.2.0
No Red Hat product state for this CVE.
github.com/beego/beego/v2
Go
Introduced 0 Fixed 2.2.1
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/beego/beego/v2 | 0 | 2.2.1 |
Remediation
No remediation recorded yet.
Weaknesses (2)
References (7)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-2441 Advisory
- https://gist.github.com/nyxfqq/a5a2fc5147a1b34538e1ac05a3e56910 Third Party Advisory
- https://github.com/advisories/GHSA-wr3p-r5fj-wf97 Advisory
- https://github.com/beego/beego/commit/5a366cd62b555354a917a2d153e6563fe4d6eb88
- https://github.com/beego/beego/commit/8f89e12e6cafb106d5c201dbc3b2a338bfde74e2
- https://github.com/beego/beego/security/advisories/GHSA-6g9p-wv47-4fxq
- https://nvd.nist.gov/vuln/detail/CVE-2024-40465
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 31, 2024
Updated Aug 2, 2024
Reserved Jul 5, 2024
Link CVE-2024-40465
CISA Vulnrichment
Updated Aug 2, 2024
Red Hat
No data
GitHub
Link GHSA-WR3P-R5FJ-WF97