github.com/dapr/dapr is vulnerable to Path Traversal
81
High Risk
Affected versions of this package are vulnerable to authorization bypass in service invocation access control policies due to inconsistent path normalization between policy enforcement and request dispatch. The affected logic evaluates method paths after decoding and normalization, while the target application receives the original raw path. An attacker able to send crafted paths containing encoded traversal sequences or reserved URL characters can cause access control checks to approve one path while a different path is executed, potentially bypassing configured method restrictions and invoking unauthorized endpoints.
You are affected if you are using a version that falls within the vulnerable range.
github.com/dapr/dapr is vulnerable to Path Traversal in versions 1.17.0 - 1.17.4, 1.16.0 - 1.16.13 and 1.3.0 - 1.15.13.
Upgrade the github.com/dapr/dapr library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant