Vulnerability Description
The package github.com/valyala/fasthttp before 1.34.0 are vulnerable to Directory Traversal via the ServeFile function, due to improper sanitization. It is possible to be exploited by using a backslash %5c character in the path. **Note:** This security issue impacts Windows users only.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fasthttp Project | Fasthttp | < 1.34.0 |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- https://github.com/valyala/fasthttp/commit/15262ecf3c602364639d465daba1e7f3604d0PatchThird Party Advisory
- https://github.com/valyala/fasthttp/commit/6b5bc7bb304975147b4af68df54ac214ed255PatchThird Party Advisory
- https://github.com/valyala/fasthttp/issues/1226ExploitIssue TrackingPatch
- https://github.com/valyala/fasthttp/releases/tag/v1.34.0Release NotesThird Party Advisory
- https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMVALYALAFASTHTTP-2407866ExploitPatchThird Party Advisory
- https://github.com/valyala/fasthttp/commit/15262ecf3c602364639d465daba1e7f3604d0PatchThird Party Advisory
- https://github.com/valyala/fasthttp/commit/6b5bc7bb304975147b4af68df54ac214ed255PatchThird Party Advisory
- https://github.com/valyala/fasthttp/issues/1226ExploitIssue TrackingPatch
- https://github.com/valyala/fasthttp/releases/tag/v1.34.0Release NotesThird Party Advisory
- https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMVALYALAFASTHTTP-2407866ExploitPatchThird Party Advisory
FAQ
What is CVE-2022-21221?
CVE-2022-21221 is a vulnerability with a CVSS score of 5.9 (MEDIUM). The package github.com/valyala/fasthttp before 1.34.0 are vulnerable to Directory Traversal via the ServeFile function, due to improper sanitization. It is possible to be exploited by using a backslas...
How severe is CVE-2022-21221?
CVE-2022-21221 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-21221?
Check the references section above for vendor advisories and patch information. Affected products include: Fasthttp Project Fasthttp, Microsoft Windows.