Critical severity9.8NVD Advisory· Published May 21, 2022· Updated Jun 17, 2026
CVE-2022-31259
CVE-2022-31259
Description
The route lookup process in beego before 1.12.9 and 2.x before 2.0.3 allows attackers to bypass access control. When a /p1/p2/:name route is configured, attackers can access it by appending .xml in various places (e.g., p1.xml instead of p1).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/beego/beego/v2Go | < 2.0.3 | 2.0.3 |
github.com/beego/beegoGo | < 1.12.9 | 1.12.9 |
Affected products
4- ghsa-coords2 versions
< 2.0.3+ 1 more
- (no CPE)range: < 2.0.3
- (no CPE)range: < 1.12.9
Patches
Vulnerability mechanics
References
10- github.com/beego/beego/issues/4946nvdExploitIssue TrackingPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-qx32-f6g6-fcfrnvdADVISORY
- github.com/beego/beego/tree/v2.0.2nvdRelease NotesThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-31259ghsaADVISORY
- beego.vipnvdProduct
- github.com/beego/beego/commit/228576173a236c81a2122923fcf8099ad294e009ghsaWEB
- github.com/beego/beego/commit/64cf44d725c8cc35d782327d333df9cbeb1bf2ddghsaWEB
- github.com/beego/beego/pull/4954ghsaWEB
- github.com/beego/beego/pull/4958ghsaWEB
- pkg.go.dev/vuln/GO-2022-0463ghsaWEB
News mentions
0No linked articles in our index yet.