Bugzilla – Full Text Bug Listing |
Summary: | VUL-0: CVE-2022-32190: go1.19: net/url: JoinPath does not strip relative path components in all circumstances | ||
---|---|---|---|
Product: | [Novell Products] SUSE Security Incidents | Reporter: | Jeff Kowalczyk <jkowalczyk> |
Component: | Incidents | Assignee: | Security Team bot <security-team> |
Status: | NEW --- | QA Contact: | Security Team bot <security-team> |
Severity: | Normal | ||
Priority: | P3 - Medium | CC: | andreas.taschner, meissner, rfrohl |
Version: | unspecified | ||
Target Milestone: | --- | ||
Hardware: | Other | ||
OS: | Other | ||
URL: | https://smash.suse.de/issue/341667/ | ||
Whiteboard: | |||
Found By: | --- | Services Priority: | |
Business Priority: | Blocker: | --- | |
Marketing QA Status: | --- | IT Deployment: | --- |
Description
Jeff Kowalczyk
2022-09-06 23:24:10 UTC
This is an autogenerated message for OBS integration: This bug (1203186) was mentioned in https://build.opensuse.org/request/show/1001534 Factory / go1.19 SUSE-SU-2022:3326-1: An update that solves two vulnerabilities and has one errata is now available. Category: security (important) Bug References: 1200441,1203185,1203186 CVE References: CVE-2022-27664,CVE-2022-32190 JIRA References: Sources used: openSUSE Leap 15.4 (src): go1.19-1.19.1-150000.1.9.1 openSUSE Leap 15.3 (src): go1.19-1.19.1-150000.1.9.1 SUSE Linux Enterprise Module for Development Tools 15-SP4 (src): go1.19-1.19.1-150000.1.9.1 SUSE Linux Enterprise Module for Development Tools 15-SP3 (src): go1.19-1.19.1-150000.1.9.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. |