Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-7187

Опубликовано: 16 фев. 2018
Источник: debian
EPSS Низкий

Описание

The "go get" implementation in Go 1.9.4, when the -insecure command-line option is used, does not validate the import path (get/vcs.go only checks for "://" anywhere in the string), which allows remote attackers to execute arbitrary OS commands via a crafted web site.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-1.10fixed1.10.1-1package
golang-1.9removedpackage
golang-1.8removedpackage
golang-1.7removedpackage
golangremovedpackage
golangignoredjessiepackage

Примечания

  • https://github.com/golang/go/issues/23867

  • https://github.com/golang/go/commit/c941e27e70c3e06e1011d2dd71d72a7a06a9bcbc

EPSS

Процентиль: 92%
0.07587
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 8 лет назад

The "go get" implementation in Go 1.9.4, when the -insecure command-line option is used, does not validate the import path (get/vcs.go only checks for "://" anywhere in the string), which allows remote attackers to execute arbitrary OS commands via a crafted web site.

CVSS3: 7.1
redhat
почти 8 лет назад

The "go get" implementation in Go 1.9.4, when the -insecure command-line option is used, does not validate the import path (get/vcs.go only checks for "://" anywhere in the string), which allows remote attackers to execute arbitrary OS commands via a crafted web site.

CVSS3: 8.8
nvd
почти 8 лет назад

The "go get" implementation in Go 1.9.4, when the -insecure command-line option is used, does not validate the import path (get/vcs.go only checks for "://" anywhere in the string), which allows remote attackers to execute arbitrary OS commands via a crafted web site.

suse-cvrf
больше 7 лет назад

Security update for go1.9

suse-cvrf
больше 7 лет назад

Security update for go1.9

EPSS

Процентиль: 92%
0.07587
Низкий