Description
The leafInfo.match() function in Beego v2.0.3 and below uses path.join() to deal with wildcardvalues which can lead to cross directory risk.
Remediation
References
Related Vulnerabilities
PrestaShop Improper Authentication Vulnerability (CVE-2020-4074)
WordPress Plugin Widgets for SiteOrigin Security Bypass (1.4.2)
Magento XML Injection (aka Blind XPath Injection) Vulnerability (CVE-2019-8158)
Oracle JRE CVE-2012-1725 Vulnerability (CVE-2012-1725)
Apache HTTP Server Use After Free Vulnerability (CVE-2019-10082)