PT-2024-11560 · Microsoft+1 · Windows+1

Juho Nurminen

·

Published

2024-07-02

·

Updated

2026-01-30

·

CVE-2022-30636

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions No specific software or versions are mentioned in the provided descriptions.
Description The issue arises from the use of path.Base to extract the expected HTTP-01 token value, which behaves differently on Windows due to the distinct path separator (`` vs /). This allows a user to provide a relative path, potentially leading to the extraction of an unintended path. The extracted path is then suffixed with +http-01 and opened. The impact is limited, as it only allows reading arbitrary files on the system if they have the +http-01 suffix.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CLEANSTART-2026-HV28992
CVE-2022-30636
GO-2024-2961

Affected Products

Debian
Windows