CVE-2022-25856

CVE-2022-25856

The package github.com/argoproj/argo-events/sensors/artifacts before 1.7.1 are vulnerable to Directory Traversal in the (g *GitArtifactReader).Read() API in git.go. This could allow arbitrary file reads if the GitArtifactReader is provided a pathname containing a symbolic link or an implicit directory name such as …

Source: CVE-2022-25856

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다