CVE Published: 13/09/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: Go |
Vendor: Go standard library |
Product: net/url Status : PUBLISHED
CVE-2022-32190 Description
JoinPath and URL.JoinPath do not remove ../ path elements appended to a relative path. For example, JoinPath("https://go.dev", "../go") returns the URL "https://go.dev/../go", despite the JoinPath documentation stating that ../ path elements are removed from the result.