PT-2022-25191 · Hertz · Hertz

Ruokeqx

·

Published

2022-09-28

·

Updated

2022-10-05

·

CVE-2022-40082

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Hertz versions prior to 0.3.1
Description The issue is related to a path traversal vulnerability via the normalizePath function. This vulnerability is caused by improper path sanitization on Windows, which permits path traversal attacks. Specifically, when using the Static or StaticFS functions for static file serving, an attacker can access files from outside the filesystem root. This issue does not affect non-Windows systems.
Recommendations For versions prior to 0.3.1, update to version 0.3.1 to resolve the issue. As a temporary workaround, consider disabling the normalizePath function or restricting access to the Static and StaticFS functions until a patch is applied.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2022-40082
GHSA-C9QR-F6C8-RGXF
GO-2022-1027

Affected Products

Hertz