Skip to content

CVE-2022-29526 @ Go-golang.org/x/sys-v0.0.0-20211216021012-1d35b9e2eb4e #104

@Yoavast

Description

@Yoavast

Checkmarx (SCA): Vulnerable Package
Vulnerability: Read More about CVE-2022-29526
Applications: yael's application
Checkmarx Project: Yoavast/CX-AST
Repository URL: https://github.com/Yoavast/CX-AST
Branch: main
Severity: MEDIUM
State: TO_VERIFY
Status: RECURRENT
Scan ID: b70b7227-90db-4075-88cb-4c196077be97


The packages golang.org/x/sys and github.com/golang/sys versions prior to v0.0.0-20220412211240-33da011f77ad has Incorrect Privilege Assignment. When called with a non-zero flags parameter, the "Faccessat" function could incorrectly report that a file is accessible.


Additional Info
Attack vector: NETWORK
Attack complexity: LOW
Confidentiality impact: LOW
Availability impact: NONE

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions