Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2023-39320

Опубликовано: 08 сент. 2023
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 9.8

Описание

The go.mod toolchain directive, introduced in Go 1.21, can be leveraged to execute scripts and binaries relative to the root of the module when the "go" command was executed within the module. This applies to modules downloaded using the "go" command from the module proxy, as well as modules downloaded directly using VCS software.

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra/focal

DNE

focal

DNE

jammy

DNE

lunar

DNE

mantic

DNE

noble

DNE

oracular

DNE

trusty

not-affected

golang 1.21 only

Показывать по

РелизСтатусПримечание
bionic

not-affected

golang 1.21 only
devel

DNE

esm-infra-legacy/trusty

not-affected

golang 1.21 only
esm-infra/bionic

not-affected

golang 1.21 only
esm-infra/focal

DNE

esm-infra/xenial

not-affected

golang 1.21 only
focal

DNE

jammy

DNE

lunar

DNE

mantic

DNE

Показывать по

РелизСтатусПримечание
bionic

not-affected

golang 1.21 only
devel

DNE

esm-apps/bionic

not-affected

golang 1.21 only
esm-apps/jammy

not-affected

golang 1.21 only
esm-apps/xenial

not-affected

golang 1.21 only
esm-infra/focal

not-affected

golang 1.21 only
focal

not-affected

golang 1.21 only
jammy

not-affected

golang 1.21 only
lunar

DNE

mantic

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra/focal

not-affected

golang 1.21 only
focal

not-affected

golang 1.21 only
jammy

DNE

lunar

DNE

mantic

DNE

noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

not-affected

golang 1.21 only
devel

DNE

esm-apps/bionic

not-affected

golang 1.21 only
esm-apps/focal

not-affected

golang 1.21 only
focal

not-affected

golang 1.21 only
jammy

DNE

lunar

DNE

mantic

DNE

noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra/focal

DNE

focal

DNE

jammy

not-affected

golang 1.21 only
lunar

DNE

mantic

DNE

noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

not-affected

golang 1.21 only
devel

DNE

esm-apps/bionic

not-affected

golang 1.21 only
esm-apps/xenial

not-affected

golang 1.21 only
focal

not-affected

golang 1.21 only
jammy

not-affected

golang 1.21 only
lunar

DNE

mantic

DNE

noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra/focal

DNE

focal

DNE

jammy

DNE

lunar

not-affected

golang 1.21 only
mantic

DNE

noble

DNE

oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

focal

not-affected

golang 1.21 only
jammy

not-affected

golang 1.21 only
lunar

not-affected

golang 1.21 only
mantic

not-affected

golang 1.21 only
noble

DNE

oracular

DNE

trusty

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-apps/noble

not-affected

1.21.5-1
focal

not-affected

1.21.1-1~ubuntu20.04.1
jammy

not-affected

1.21.1-1~ubuntu22.04.1
lunar

not-affected

1.21.1-1~ubuntu23.04.1
mantic

not-affected

1.21.1-1
noble

not-affected

1.21.5-1
oracular

DNE

trusty

DNE

Показывать по

РелизСтатусПримечание
bionic

DNE

devel

DNE

esm-infra/focal

DNE

esm-infra/xenial

not-affected

golang 1.21 only
focal

DNE

jammy

DNE

lunar

DNE

mantic

DNE

noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

not-affected

golang 1.21 only
devel

DNE

esm-apps/bionic

not-affected

golang 1.21 only
esm-infra/focal

DNE

focal

DNE

jammy

DNE

lunar

DNE

mantic

DNE

noble

DNE

oracular

DNE

Показывать по

РелизСтатусПримечание
bionic

not-affected

golang 1.21 only
devel

DNE

esm-apps/bionic

not-affected

golang 1.21 only
esm-infra/focal

DNE

focal

DNE

jammy

DNE

lunar

DNE

mantic

DNE

noble

DNE

oracular

DNE

Показывать по

EPSS

Процентиль: 74%
0.00798
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 8.8
redhat
больше 2 лет назад

The go.mod toolchain directive, introduced in Go 1.21, can be leveraged to execute scripts and binaries relative to the root of the module when the "go" command was executed within the module. This applies to modules downloaded using the "go" command from the module proxy, as well as modules downloaded directly using VCS software.

CVSS3: 9.8
nvd
больше 2 лет назад

The go.mod toolchain directive, introduced in Go 1.21, can be leveraged to execute scripts and binaries relative to the root of the module when the "go" command was executed within the module. This applies to modules downloaded using the "go" command from the module proxy, as well as modules downloaded directly using VCS software.

CVSS3: 9.8
debian
больше 2 лет назад

The go.mod toolchain directive, introduced in Go 1.21, can be leverage ...

CVSS3: 9.8
github
больше 2 лет назад

The go.mod toolchain directive, introduced in Go 1.21, can be leveraged to execute scripts and binaries relative to the root of the module when the "go" command was executed within the module. This applies to modules downloaded using the "go" command from the module proxy, as well as modules downloaded directly using VCS software.

CVSS3: 9.8
fstec
больше 2 лет назад

Уязвимость файла go.mod языка программирования Go, позволяющая нарушителю повысить свои привилегии и выполнить произвольный код

EPSS

Процентиль: 74%
0.00798
Низкий

9.8 Critical

CVSS3

Уязвимость CVE-2023-39320