Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-23773

Опубликовано: 11 фев. 2022
Источник: debian
EPSS Низкий

Описание

cmd/go in Go before 1.16.14 and 1.17.x before 1.17.7 can misinterpret branch names that falsely appear to be version tags. This can lead to incorrect access control if an actor is supposed to be able to create branches but not tags.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
golang-1.18fixed1.18~rc1-1package
golang-1.17fixed1.17.7-1package
golang-1.15removedpackage
golang-1.15fixed1.15.15-1~deb11u3bullseyepackage
golang-1.11removedpackage
golang-1.11ignoredbusterpackage
golang-1.8removedpackage
golang-1.8not-affectedstretchpackage
golang-1.7removedpackage
golang-1.7not-affectedstretchpackage

Примечания

  • https://github.com/golang/go/issues/35671

  • https://groups.google.com/g/golang-announce/c/SUsQn0aSgPQ

  • https://github.com/golang/go/commit/fbcc30a2c9d076b27b4b411e2cec91ec13528081 (go1.17.7)

EPSS

Процентиль: 19%
0.00058
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 3 лет назад

cmd/go in Go before 1.16.14 and 1.17.x before 1.17.7 can misinterpret branch names that falsely appear to be version tags. This can lead to incorrect access control if an actor is supposed to be able to create branches but not tags.

CVSS3: 7.5
redhat
больше 3 лет назад

cmd/go in Go before 1.16.14 and 1.17.x before 1.17.7 can misinterpret branch names that falsely appear to be version tags. This can lead to incorrect access control if an actor is supposed to be able to create branches but not tags.

CVSS3: 7.5
nvd
больше 3 лет назад

cmd/go in Go before 1.16.14 and 1.17.x before 1.17.7 can misinterpret branch names that falsely appear to be version tags. This can lead to incorrect access control if an actor is supposed to be able to create branches but not tags.

CVSS3: 7.5
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 7.5
github
больше 3 лет назад

cmd/go in Go before 1.16.14 and 1.17.x before 1.17.7 can misinterpret branch names that falsely appear to be version tags. This can lead to incorrect access control if an actor is supposed to be able to create branches but not tags.

EPSS

Процентиль: 19%
0.00058
Низкий