Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5m4p-2gjx-p2g8

Опубликовано: 07 мая 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp"). An attacker with access to the temporary directory can create a symlink in one of these names, causing "go bug" to overwrite the target of the symlink.

The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp"). An attacker with access to the temporary directory can create a symlink in one of these names, causing "go bug" to overwrite the target of the symlink.

EPSS

Процентиль: 8%
0.00179
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
3 месяца назад

The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp"). An attacker with access to the temporary directory can create a symlink in one of these names, causing "go bug" to overwrite the target of the symlink.

CVSS3: 5.3
nvd
3 месяца назад

The "go bug" command writes to two files with predictable names in the system temporary directory (for example, "/tmp"). An attacker with access to the temporary directory can create a symlink in one of these names, causing "go bug" to overwrite the target of the symlink.

msrc
3 месяца назад

Invoking "go bug" follows symlinks in predictable temporary filenames in cmd/go

CVSS3: 5.3
debian
3 месяца назад

The "go bug" command writes to two files with predictable names in the ...

CVSS3: 5.3
fstec
4 месяца назад

Уязвимость команды go bug языка программирования Go, позволяющая нарушителю получить доступ на чтение и запись произвольных файлов

EPSS

Процентиль: 8%
0.00179
Низкий

5.3 Medium

CVSS3