Vulnerabilities
Vulnerable Software
Golang:  >> Go  >> 1.18.9  Security Vulnerabilities
A path traversal vulnerability exists in filepath.Clean on Windows. On Windows, the filepath.Clean function could transform an invalid path such as "a/../c:/b" into the valid path "c:\b". This transformation of a relative (if invalid) path into an absolute path could enable a directory traversal attack. After fix, the filepath.Clean function transforms this path into the relative (but still invalid) path ".\c:\b".
CVSS Score
7.5
EPSS Score
0.001
Published
2023-02-28
A maliciously crafted HTTP/2 stream could cause excessive CPU consumption in the HPACK decoder, sufficient to cause a denial of service from a small number of small requests.
CVSS Score
7.5
EPSS Score
0.002
Published
2023-02-28


Contact Us

Shodan ® - All rights reserved