CVE-2022-31259

The route lookup process in beego before 1.12.9 and 2.x before 2.0.3 allows attackers to bypass access control. When a /p1/p2/:name route is configured, attackers can access it by appending .xml in various places (e.g., p1.xml instead of p1).
References
Link Resource
https://beego.vip Product
https://github.com/advisories/GHSA-qx32-f6g6-fcfr
https://github.com/beego/beego/issues/4946 Exploit Issue Tracking Patch Third Party Advisory
https://github.com/beego/beego/tree/v2.0.2 Release Notes Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:beego:beego:*:*:*:*:*:*:*:*
cpe:2.3:a:beego:beego:*:*:*:*:*:*:*:*

History

17 Feb 2023, 17:15

Type Values Removed Values Added
References
  • (MISC) https://github.com/advisories/GHSA-qx32-f6g6-fcfr -
Summary The route lookup process in beego through 1.12.4 and 2.x through 2.0.2 allows attackers to bypass access control. When a /p1/p2/:name route is configured, attackers can access it by appending .xml in various places (e.g., p1.xml instead of p1). The route lookup process in beego before 1.12.9 and 2.x before 2.0.3 allows attackers to bypass access control. When a /p1/p2/:name route is configured, attackers can access it by appending .xml in various places (e.g., p1.xml instead of p1).

02 Jun 2022, 19:02

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 6.8
v3 : 9.8
References (MISC) https://beego.vip - (MISC) https://beego.vip - Product
References (MISC) https://github.com/beego/beego/issues/4946 - (MISC) https://github.com/beego/beego/issues/4946 - Exploit, Issue Tracking, Patch, Third Party Advisory
References (MISC) https://github.com/beego/beego/tree/v2.0.2 - (MISC) https://github.com/beego/beego/tree/v2.0.2 - Release Notes, Third Party Advisory
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:beego:beego:*:*:*:*:*:*:*:*

21 May 2022, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-05-21 19:15

Updated : 2024-02-04 22:29


NVD link : CVE-2022-31259

Mitre link : CVE-2022-31259

CVE.ORG link : CVE-2022-31259


JSON object : View

Products Affected

beego

  • beego