Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xm99-6pv5-q363

Опубликовано: 23 апр. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.8

Описание

Disputed: OS Command injection in github.com/kardianos/service

service_windows.go in the kardianos service package for Go omits quoting that is sometimes needed for execution of a Windows service executable from the intended directory.

The validity of this vulnerability has been questioned and the reporter has requested that the CVE be disputed.

Пакеты

Наименование

github.com/kardianos/service

go
Затронутые версииВерсия исправления

<= 1.2.1

Отсутствует

EPSS

Процентиль: 20%
0.00063
Низкий

7.8 High

CVSS3

Дефекты

CWE-426
CWE-78

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 4 года назад

service_windows.go in the kardianos service package for Go omits quoting that is sometimes needed for execution of a Windows service executable from the intended directory. NOTE: this finding could not be reproduced by its original reporter or by others.

CVSS3: 7.8
nvd
почти 4 года назад

service_windows.go in the kardianos service package for Go omits quoting that is sometimes needed for execution of a Windows service executable from the intended directory. NOTE: this finding could not be reproduced by its original reporter or by others.

CVSS3: 7.8
debian
почти 4 года назад

service_windows.go in the kardianos service package for Go omits quoti ...

EPSS

Процентиль: 20%
0.00063
Низкий

7.8 High

CVSS3

Дефекты

CWE-426
CWE-78