CVE-2022-31836Critical· 9.8▾ MidnightPath Traversal in Beego
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.5%
1.5% → 1.7%
The leafInfo.match() function in Beego v2.0.3 and below uses path.join() to deal with wildcardvalues which can lead to cross directory risk.
github.com/beego/beego < 1.12.11github.com/beego/beego/v2 >= 2.0.0, < 2.0.4Upgrade to a patched release:
github.com/beego/beego 1.12.11github.com/beego/beego/v2 2.0.4Connected by shared product, vendor, weakness, or advisory.