GHSA-xm99-6pv5-q363
Dashboard / Vulnerabilities / GHSA-xm99-6pv5-q363
Summary: Disputed: OS Command injection in github.com/kardianos/service
Details: service_windows.go in the kardianos service package for Go omits quoting that is sometimes needed for execution of a Windows service executable from the intended directory. The validity of this vulnerability has been [questioned](https://github.com/kardianos/service/pull/290#issuecomment-1109831505) and the reporter has requested that the CVE be [disputed](https://github.com/kardianos/service/issues/289#issuecomment-1110546798).
References: https://nvd.nist.gov/vuln/detail/CVE-2022-29583, https://github.com/kardianos/service/issues/289, https://github.com/kardianos/service/pull/290, https://github.com/kardianos/service
Affected packages
Package
Name: github.com/kardianos/service
Purl: pkg:golang/github.com/kardianos/service
Affected ranges
Type: SEMVER
Events:
