Vulnerability Report: GO-2022-0492
- CVE-2022-25856, GHSA-qpgx-64h2-gc3c
- Affects: github.com/argoproj/argo-events
- Published: Jul 15, 2022
- Modified: May 20, 2024
GitArtifactReader is vulnerable to directory traversal attacks. The GitArtifactReader.Read function reads and returns the contents of a Git repository file. A maliciously crafted repository can exploit this to cause Read to read from arbitrary files on the filesystem.
Affected Packages
-
PathGo VersionsSymbols
-
before v1.7.1
Aliases
References
- https://github.com/argoproj/argo-events/pull/1965
- https://github.com/argoproj/argo-events/issues/1947
- https://vuln.go.dev/ID/GO-2022-0492.json
Credits
- Derek Wang
Feedback
See anything missing or incorrect?
Suggest an edit to this report.