Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-30580

Опубликовано: 10 авг. 2022
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.8

Описание

Code injection in Cmd.Start in os/exec before Go 1.17.11 and Go 1.18.3 allows execution of any binaries in the working directory named either "..com" or "..exe" by calling Cmd.Run, Cmd.Start, Cmd.Output, or Cmd.CombinedOutput when Cmd.Path is unset.

РелизСтатусПримечание
upstream

not-affected

debian: Only affects Go on Windows

Показывать по

РелизСтатусПримечание
impish

not-affected

windows only
upstream

not-affected

debian: Only affects Go on Windows

Показывать по

РелизСтатусПримечание
devel

DNE

impish

not-affected

windows only
jammy

not-affected

windows only
kinetic

DNE

lunar

DNE

upstream

not-affected

debian: Only affects Go on Windows

Показывать по

РелизСтатусПримечание
bionic

not-affected

windows only
devel

DNE

esm-infra/focal

DNE

focal was not-affected [windows only]
focal

not-affected

windows only
jammy

not-affected

windows only
kinetic

DNE

lunar

DNE

upstream

not-affected

debian: Only affects Go on Windows

Показывать по

РелизСтатусПримечание
upstream

not-affected

debian: Only affects Go on Windows

Показывать по

РелизСтатусПримечание
bionic

not-affected

windows only
esm-apps/bionic

not-affected

windows only
upstream

not-affected

debian: Only affects Go on Windows

Показывать по

EPSS

Процентиль: 4%
0.00022
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
redhat
почти 3 года назад

Code injection in Cmd.Start in os/exec before Go 1.17.11 and Go 1.18.3 allows execution of any binaries in the working directory named either "..com" or "..exe" by calling Cmd.Run, Cmd.Start, Cmd.Output, or Cmd.CombinedOutput when Cmd.Path is unset.

CVSS3: 7.8
nvd
почти 3 года назад

Code injection in Cmd.Start in os/exec before Go 1.17.11 and Go 1.18.3 allows execution of any binaries in the working directory named either "..com" or "..exe" by calling Cmd.Run, Cmd.Start, Cmd.Output, or Cmd.CombinedOutput when Cmd.Path is unset.

CVSS3: 7.8
msrc
почти 3 года назад

Описание отсутствует

CVSS3: 7.8
debian
почти 3 года назад

Code injection in Cmd.Start in os/exec before Go 1.17.11 and Go 1.18.3 ...

CVSS3: 7.8
github
почти 3 года назад

Code injection in Cmd.Start in os/exec before Go 1.17.11 and Go 1.18.3 allows execution of any binaries in the working directory named either "..com" or "..exe" by calling Cmd.Run, Cmd.Start, Cmd.Output, or Cmd.CombinedOutput when Cmd.Path is unset.

EPSS

Процентиль: 4%
0.00022
Низкий

7.8 High

CVSS3