Vulnerability CVE-2020-36559


Published: 2022-12-27

Description:
Due to improper santization of user input, HTTPEngine.Handle allows for directory traversal, allowing an attacker to read files outside of the target directory that the server has permission to read.

 References:
https://github.com/go-aah/aah/pull/267
https://github.com/go-aah/aah/issues/266
https://pkg.go.dev/vuln/GO-2020-0033
https://github.com/go-aah/aah/commit/881dc9f71d1f7a4e8a9a39df9c5c081d3a2da1ec

Copyright 2026, cxsecurity.com

 

Back to Top