Описание
The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames. Extracting a malicious archive file with the "pack" subcommand can write files to arbitrary locations on the filesystem.
A flaw was found in the "go tool pack" subcommand, a component of the Go programming language tools. This vulnerability allows an attacker to craft a malicious archive file. When this archive is extracted using the "pack" subcommand, it can lead to arbitrary file writes on the filesystem, potentially allowing an attacker to create or modify files in unintended locations.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Multicluster Engine for Kubernetes | multicluster-engine/addon-manager-rhel9 | Under investigation | ||
| Multicluster Engine for Kubernetes | multicluster-engine/backplane-rhel9-operator | Under investigation | ||
| Multicluster Engine for Kubernetes | multicluster-engine/clusterlifecycle-state-metrics-rhel9 | Under investigation | ||
| Multicluster Engine for Kubernetes | multicluster-engine/hypershift-addon-rhel9-operator | Under investigation | ||
| Multicluster Engine for Kubernetes | multicluster-engine/maestro-rhel9 | Under investigation | ||
| Multicluster Engine for Kubernetes | multicluster-engine/managedcluster-import-controller-rhel9 | Under investigation | ||
| Multicluster Engine for Kubernetes | multicluster-engine/multicloud-manager-rhel9 | Under investigation | ||
| Multicluster Engine for Kubernetes | multicluster-engine/placement-rhel9 | Under investigation | ||
| Multicluster Engine for Kubernetes | multicluster-engine/registration-operator-rhel9 | Under investigation | ||
| Multicluster Engine for Kubernetes | multicluster-engine/work-rhel9 | Under investigation |
Показывать по
Дополнительная информация
Статус:
EPSS
5.9 Medium
CVSS3
Связанные уязвимости
The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames. Extracting a malicious archive file with the "pack" subcommand can write files to arbitrary locations on the filesystem.
The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames. Extracting a malicious archive file with the "pack" subcommand can write files to arbitrary locations on the filesystem.
The "go tool pack" subcommand (usually used only by the compiler as an ...
The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sanitize output filenames. Extracting a malicious archive file with the "pack" subcommand can write files to arbitrary locations on the filesystem.
EPSS
5.9 Medium
CVSS3