Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 7

Количество 7

fstec логотип

BDU:2024-08391

почти 3 года назад

Уязвимость языка программирования Golang, связанная с непринятием мер по нейтрализации специальных элементов, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
EPSS: Низкий
redos логотип

ROS-20241015-09

почти 2 года назад

Уязвимость golang

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2023-24531

около 2 лет назад

Command go env is documented as outputting a shell script containing the Go environment. However, go env doesn't sanitize values, so executing its output as a shell script can cause various bad bahaviors, including executing arbitrary commands or inserting new environment variables. This issue is relatively minor because, in general, if an attacker can set arbitrary environment variables on a system, they have better attack vectors than making "go env" print them out.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2023-24531

около 2 лет назад

Command go env is documented as outputting a shell script containing the Go environment. However, go env doesn't sanitize values, so executing its output as a shell script can cause various bad bahaviors, including executing arbitrary commands or inserting new environment variables. This issue is relatively minor because, in general, if an attacker can set arbitrary environment variables on a system, they have better attack vectors than making "go env" print them out.

CVSS3: 9.8
EPSS: Низкий
msrc логотип

CVE-2023-24531

11 месяцев назад

Output of "go env" does not sanitize values in cmd/go

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2023-24531

около 2 лет назад

Command go env is documented as outputting a shell script containing t ...

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-cwpg-qgc6-jxvq

около 2 лет назад

Command go env is documented as outputting a shell script containing the Go environment. However, go env doesn't sanitize values, so executing its output as a shell script can cause various bad bahaviors, including executing arbitrary commands or inserting new environment variables. This issue is relatively minor because, in general, if an attacker can set arbitrary environment variables on a system, they have better attack vectors than making "go env" print them out.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2024-08391

Уязвимость языка программирования Golang, связанная с непринятием мер по нейтрализации специальных элементов, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
1%
Низкий
почти 3 года назад
redos логотип
ROS-20241015-09

Уязвимость golang

CVSS3: 5.3
1%
Низкий
почти 2 года назад
ubuntu логотип
CVE-2023-24531

Command go env is documented as outputting a shell script containing the Go environment. However, go env doesn't sanitize values, so executing its output as a shell script can cause various bad bahaviors, including executing arbitrary commands or inserting new environment variables. This issue is relatively minor because, in general, if an attacker can set arbitrary environment variables on a system, they have better attack vectors than making "go env" print them out.

CVSS3: 9.8
1%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-24531

Command go env is documented as outputting a shell script containing the Go environment. However, go env doesn't sanitize values, so executing its output as a shell script can cause various bad bahaviors, including executing arbitrary commands or inserting new environment variables. This issue is relatively minor because, in general, if an attacker can set arbitrary environment variables on a system, they have better attack vectors than making "go env" print them out.

CVSS3: 9.8
1%
Низкий
около 2 лет назад
msrc логотип
CVE-2023-24531

Output of "go env" does not sanitize values in cmd/go

CVSS3: 9.8
1%
Низкий
11 месяцев назад
debian логотип
CVE-2023-24531

Command go env is documented as outputting a shell script containing t ...

CVSS3: 9.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-cwpg-qgc6-jxvq

Command go env is documented as outputting a shell script containing the Go environment. However, go env doesn't sanitize values, so executing its output as a shell script can cause various bad bahaviors, including executing arbitrary commands or inserting new environment variables. This issue is relatively minor because, in general, if an attacker can set arbitrary environment variables on a system, they have better attack vectors than making "go env" print them out.

CVSS3: 9.8
1%
Низкий
около 2 лет назад

Уязвимостей на страницу