Property
Languagego
Severitymedium
CWECWE-548: Exposure of Information Through Directory Listing
OWASPA06:2017 - Security Misconfiguration
Confidence LevelMedium
Impact LevelMedium
Likelihood LevelMedium

Description#

Using http.FileServer as a handler in Go exposes directory contents to anyone with access to the server. This allows users to browse all files in the served directory, which may unintentionally reveal sensitive files.

Impact#

If exploited, attackers can view or download files not meant for public access, such as configuration files, credentials, or source code. This can lead to data leaks, information disclosure, and further attacks against your system.