Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r4gv-vj59-cccm

Опубликовано: 23 июн. 2021
Источник: github
Github: Прошло ревью
CVSS3: 6.8

Описание

Control character injection in console output in github.com/ipfs/go-ipfs

Impact

Control characters are not escaped from console output. This can result in hiding input from the user which could result in the user taking an unknown, malicious action.

Patches

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

github.com/ipfs/go-ipfs

go
Затронутые версииВерсия исправления

< 0.8.0

0.8.0

EPSS

Процентиль: 75%
0.00858
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-116
CWE-150

Связанные уязвимости

CVSS3: 6.8
nvd
почти 5 лет назад

go-ipfs is an open-source golang implementation of IPFS which is a global, versioned, peer-to-peer filesystem. In go-ipfs before version 0.8.0, control characters are not escaped from console output. This can result in hiding input from the user which could result in the user taking an unknown, malicious action. This is fixed in version 0.8.0.

CVSS3: 6.8
debian
почти 5 лет назад

go-ipfs is an open-source golang implementation of IPFS which is a glo ...

EPSS

Процентиль: 75%
0.00858
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-116
CWE-150