Improper path sanitization in github.com/goadesign/goa before v3.0.9, v2.0.10, or v1.4.3 allow remote attackers to read files outside of the intended directory.
{
"source": [
"CPE_RANGE",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "1.4.3"
},
{
"introduced": "2.0.0"
},
{
"fixed": "2.0.10"
},
{
"introduced": "3.0.0"
},
{
"fixed": "3.0.9"
}
],
"cpe": "cpe:2.3:a:goa.design:goa:*:*:*:*:*:go:*:*"
}