CVE-2020-36559 Information

Description

Due to improper santization of user input HTTPEngine.Handle allows for directory traversal allowing an attacker to read files outside of the target directory that the server has permission to read.

Reference

https://github.com/go-aah/aah/pull/267 https://github.com/go-aah/aah/issues/266 https://pkg.go.dev/vuln/GO-2020-0033 https://github.com/go-aah/aah/commit/881dc9f71d1f7a4e8a9a39df9c5c081d3a2da1ec

Share on: