Логотип exploitDog
bind: "CVE-2023-24531"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2023-24531"

Количество 6

Количество 6

ubuntu логотип

CVE-2023-24531

12 месяцев назад

Command go env is documented as outputting a shell script containing the Go environment. However, go env doesn't sanitize values, so executing its output as a shell script can cause various bad bahaviors, including executing arbitrary commands or inserting new environment variables. This issue is relatively minor because, in general, if an attacker can set arbitrary environment variables on a system, they have better attack vectors than making "go env" print them out.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2023-24531

12 месяцев назад

Command go env is documented as outputting a shell script containing the Go environment. However, go env doesn't sanitize values, so executing its output as a shell script can cause various bad bahaviors, including executing arbitrary commands or inserting new environment variables. This issue is relatively minor because, in general, if an attacker can set arbitrary environment variables on a system, they have better attack vectors than making "go env" print them out.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2023-24531

12 месяцев назад

Command go env is documented as outputting a shell script containing t ...

CVSS3: 9.8
EPSS: Низкий
redos логотип

ROS-20241015-09

8 месяцев назад

Уязвимость golang

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-cwpg-qgc6-jxvq

12 месяцев назад

Command go env is documented as outputting a shell script containing the Go environment. However, go env doesn't sanitize values, so executing its output as a shell script can cause various bad bahaviors, including executing arbitrary commands or inserting new environment variables. This issue is relatively minor because, in general, if an attacker can set arbitrary environment variables on a system, they have better attack vectors than making "go env" print them out.

CVSS3: 9.8
EPSS: Низкий
fstec логотип

BDU:2024-08391

почти 2 года назад

Уязвимость языка программирования Golang, связанная с непринятием мер по нейтрализации специальных элементов, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-24531

Command go env is documented as outputting a shell script containing the Go environment. However, go env doesn't sanitize values, so executing its output as a shell script can cause various bad bahaviors, including executing arbitrary commands or inserting new environment variables. This issue is relatively minor because, in general, if an attacker can set arbitrary environment variables on a system, they have better attack vectors than making "go env" print them out.

CVSS3: 9.8
1%
Низкий
12 месяцев назад
nvd логотип
CVE-2023-24531

Command go env is documented as outputting a shell script containing the Go environment. However, go env doesn't sanitize values, so executing its output as a shell script can cause various bad bahaviors, including executing arbitrary commands or inserting new environment variables. This issue is relatively minor because, in general, if an attacker can set arbitrary environment variables on a system, they have better attack vectors than making "go env" print them out.

CVSS3: 9.8
1%
Низкий
12 месяцев назад
debian логотип
CVE-2023-24531

Command go env is documented as outputting a shell script containing t ...

CVSS3: 9.8
1%
Низкий
12 месяцев назад
redos логотип
ROS-20241015-09

Уязвимость golang

CVSS3: 5.3
1%
Низкий
8 месяцев назад
github логотип
GHSA-cwpg-qgc6-jxvq

Command go env is documented as outputting a shell script containing the Go environment. However, go env doesn't sanitize values, so executing its output as a shell script can cause various bad bahaviors, including executing arbitrary commands or inserting new environment variables. This issue is relatively minor because, in general, if an attacker can set arbitrary environment variables on a system, they have better attack vectors than making "go env" print them out.

CVSS3: 9.8
1%
Низкий
12 месяцев назад
fstec логотип
BDU:2024-08391

Уязвимость языка программирования Golang, связанная с непринятием мер по нейтрализации специальных элементов, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
1%
Низкий
почти 2 года назад

Уязвимостей на страницу