Hertz contains path traversal via normalizePath function
High severity
GitHub Reviewed
Published
Sep 29, 2022
to the GitHub Advisory Database
•
Updated Feb 14, 2023
Description
Published by the National Vulnerability Database
Sep 28, 2022
Published to the GitHub Advisory Database
Sep 29, 2022
Reviewed
Sep 30, 2022
Last updated
Feb 14, 2023
Hertz is a a high-performance and strong-extensibility Go HTTP framework that helps developers build microservices. Versions of Hertz prior to 0.3.1 contain a path traversal vulnerability via the normalizePath function. This issue has been patched in 0.3.1.
References