CVE-2026-55677

Red Hat Security Advisory: Cluster Observability Operator 1.5.2

Beschreibung

Echo ist ein Go-Webframework. Vor Versionen 4.15.3 und 5.2.0 stimmen Echos Router und der statische Dateihandler nicht überein, wenn es um die Dekodierung von URL-Pfaden geht. Der Router verwendet den roh kodierten Pfad (er behält %2F unverändert bei), während StaticDirectoryHandler %2F in / dekodiert, bevor er Dateisystempfade auflöst. Dies ermöglicht einem Angreifer, Zugriffskontrollen auf Routenebene zu umgehen und statische Dateien ohne Autorisierung einzusehen. Diese Schwachstelle wurde in den Versionen 4.15.3 und 5.2.0 behoben.

Metriken

Severity
high
kein öffentlicher PoC bekannt
7.5
Quelle: nvd-v3
36.3 %
Hoch — CVE rangiert über dem Median aller heute bewerteten CVEs (Rang ≥ 36 %).
0.4 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-08-31 07:19 UTC
CWE-22

Weakness-Klassen (CWE)

  • CWE-22Base

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

    cwe.mitre.org →

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • bitnami

    golang1.26.0-0

  • go

    github.com/go-git/go-billy/v5

  • go

    github.com/labstack/echo/v4

  • go

    github.com/labstack/echo/v5

  • go

    go.opentelemetry.io/otel1.41.0

  • go

    go.opentelemetry.io/otel1.43.0

  • go

    golang.org/x/crypto

  • go

    golang.org/x/net

  • go

    golang.org/x/text

  • go

    stdlib1.26.0-0

  • go

    stdlib1.27.0-0

  • golang

    crypto0.52.0

  • IBM

    App Connect Enterprise< 12.0.12.28

    gefixt in 12.0.12.28

  • IBM

    App Connect Enterprise< 13.0.8.1

    gefixt in 13.0.8.1

  • IBM

    App Connect Enterprise< 13.0.8.2

    gefixt in 13.0.8.2

  • IBM

    Concert< 3.0.0

    gefixt in 3.0.0

  • jsonparser_project

    jsonparser1.1.2

  • openjsf

    fast-uri2.3.1 – 3.1.3

  • openjsf

    fast-uri4.0.0 – 4.0.1

  • opentelemetry

    opentelemetry1.36.0 – 1.41.0

Quellen & Referenzen

Verknüpfte CVEs

IDCVE-2026-55677