Improper path handling in kustomization files allows path traversal in github.com/fluxcd/flux2
{ "review_status": "UNREVIEWED", "url": "https://pkg.go.dev/vuln/GO-2022-0447" }