Junglewise Threat Intelligence

CVE-2022-24877: GO-2022-0447 - Improper path handling in kustomization files allows path traversal in github.com/fluxcd/flux2

CVE-2022-24877 · Severity: low · CVSS 3.1 · Published 2024-08-21

Technologies: github.com/fluxcd/flux2 (Go), github.com/fluxcd/kustomize-controller (Go). Vendors: Go.

Executive brief

Improper path handling in kustomization files allows path traversal in github.com/fluxcd/flux2

Affected products

  • Go github.com/fluxcd/flux2
  • Go github.com/fluxcd/kustomize-controller

Related threats