Vulnerability Report: GO-2022-1031
- CVE-2022-40083, GHSA-crxj-hrmp-4rwf
- Affects: github.com/labstack/echo/v4
- Published: Oct 11, 2022
- Modified: May 20, 2024
Labstack Echo contains an open redirect vulnerability via the Static Handler component. This vulnerability can be leveraged by attackers to cause a Server-Side Request Forgery (SSRF).
Affected Packages
-
PathGo VersionsSymbols
-
before v4.9.0
5 affected symbols
Aliases
References
- https://github.com/labstack/echo/issues/2259
- https://github.com/labstack/echo/pull/2260
- https://vuln.go.dev/ID/GO-2022-1031.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.