Beego Framework Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability - CVE-2022-31836 - Vulnerability Database

Beego Framework Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability - CVE-2022-31836

Critical
Reference: CVE-2022-31836
Title: Beego Framework Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability
Overview:

The leafInfo.match() function in Beego v2.0.3 and below uses path.join() to deal with wildcardvalues which can lead to cross directory risk.