Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-79cw-x93g-q95p

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Go before 1.14.14 and 1.15.x before 1.15.7 on Windows is vulnerable to Command Injection and remote code execution when using the "go get" command to fetch modules that make use of cgo (for example, cgo can execute a gcc program from an untrusted download).

Go before 1.14.14 and 1.15.x before 1.15.7 on Windows is vulnerable to Command Injection and remote code execution when using the "go get" command to fetch modules that make use of cgo (for example, cgo can execute a gcc program from an untrusted download).

EPSS

Процентиль: 30%
0.00107
Низкий

7.5 High

CVSS3

Дефекты

CWE-427
CWE-77
CWE-94

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 4 лет назад

Go before 1.14.14 and 1.15.x before 1.15.7 on Windows is vulnerable to Command Injection and remote code execution when using the "go get" command to fetch modules that make use of cgo (for example, cgo can execute a gcc program from an untrusted download).

CVSS3: 7.5
redhat
больше 4 лет назад

Go before 1.14.14 and 1.15.x before 1.15.7 on Windows is vulnerable to Command Injection and remote code execution when using the "go get" command to fetch modules that make use of cgo (for example, cgo can execute a gcc program from an untrusted download).

CVSS3: 7.5
nvd
больше 4 лет назад

Go before 1.14.14 and 1.15.x before 1.15.7 on Windows is vulnerable to Command Injection and remote code execution when using the "go get" command to fetch modules that make use of cgo (for example, cgo can execute a gcc program from an untrusted download).

CVSS3: 7.5
msrc
12 месяцев назад

Описание отсутствует

CVSS3: 7.5
debian
больше 4 лет назад

Go before 1.14.14 and 1.15.x before 1.15.7 on Windows is vulnerable to ...

EPSS

Процентиль: 30%
0.00107
Низкий

7.5 High

CVSS3

Дефекты

CWE-427
CWE-77
CWE-94