GHSA-rrp4-2xx3-mv29

    Dashboard / Vulnerabilities / GHSA-rrp4-2xx3-mv29

    GHSA-rrp4-2xx3-mv29

    Published: 1 Feb 2022Last Modified: 10 Sept 2026

    Summary: Command injection in gh-ost

    Details: Gh-ost version <= 1.1.2 allows users to inject DSN strings via the `-database` parameter. This is a low severity vulnerability as the attacker must have access to the target host or trick an administrator into executing a malicious `gh-ost` command on a host running `gh-ost`, plus network access from host running `gh-ost` to the attack's malicious MySQL server. ### Impact This issue may lead to arbitrary local file read. ### Patches Fixed in 1.1.3+. ### Workarounds None ### References - https://advisory.dw1.io/51 ### For more information If you have any questions or comments about this advisory: * Open an issue in [github/gh-ost](http://github.com/github/gh-ost)

    Affected packages

    Package

    Name: github.com/github/gh-ost

    Purl: pkg:golang/github.com/github/gh-ost

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -1.1.3

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-rrp4-2xx3-mv29 | CVE-DB