Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Echo: Encoded slash (%2F) bypasses route-level protection and exposes static files
Vulnerability Description
Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo's router and static file handler disagree on URL path decoding. The router matches routes using the raw encoded path (preserving %2F as-is), while StaticDirectoryHandler unescapes %2F to / before resolving filesystem paths. This allows an attacker to bypass route-level access controls and read static files without authorization. This vulnerability is fixed in 4.15.3 and 5.2.0.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
labstack echo 路径遍历漏洞
Vulnerability Description
labstack echo是labstack个人开发者开源的一款高性能Web框架。 labstack echo 4.15.3之前版本和5.0.0及以上5.2.0之前版本存在路径遍历漏洞,该漏洞源于路由器和静态文件处理程序对URL路径解码的不一致,可能导致攻击者绕过路由级访问控制并未授权读取静态文件。
CVSS Information
N/A
Vulnerability Type
N/A