Vulnerability Description
The package github.com/argoproj/argo-events/sensors/artifacts before 1.7.1 are vulnerable to Directory Traversal in the (g *GitArtifactReader).Read() API in git.go. This could allow arbitrary file reads if the GitArtifactReader is provided a pathname containing a symbolic link or an implicit directory name such as ...
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Argo Events Project | Argo Events | < 1.7.1 |
Related Weaknesses (CWE)
References
- https://github.com/argoproj/argo-events/commit/d0f66dbce78bc31923ca057b20fc722aaPatchThird Party Advisory
- https://github.com/argoproj/argo-events/issues/1947ExploitIssue TrackingThird Party Advisory
- https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMARGOPROJARGOEVENTSSENSORSARTIFACTS-286ExploitPatchThird Party Advisory
- https://github.com/argoproj/argo-events/commit/d0f66dbce78bc31923ca057b20fc722aaPatchThird Party Advisory
- https://github.com/argoproj/argo-events/issues/1947ExploitIssue TrackingThird Party Advisory
- https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMARGOPROJARGOEVENTSSENSORSARTIFACTS-286ExploitPatchThird Party Advisory
FAQ
What is CVE-2022-25856?
CVE-2022-25856 is a vulnerability with a CVSS score of 7.5 (HIGH). The package github.com/argoproj/argo-events/sensors/artifacts before 1.7.1 are vulnerable to Directory Traversal in the (g *GitArtifactReader).Read() API in git.go. This could allow arbitrary file rea...
How severe is CVE-2022-25856?
CVE-2022-25856 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-25856?
Check the references section above for vendor advisories and patch information. Affected products include: Argo Events Project Argo Events.