Security Advisory

CVE-2022-25856

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-06-17 20:00:17
Last updated 2024-09-17 04:24:21
Assigner snyk
State PUBLISHED

Description

The package github.com/argoproj/argo-events/sensors/artifacts before 1.7.1 are vulnerable to Directory Traversal in the (g *GitArtifactReader).Read() API in git.go. This could allow arbitrary file reads if the GitArtifactReader is provided a pathname containing a symbolic link or an implicit directory name such as ...