GO-2021-0068
Dashboard / Vulnerabilities / GO-2021-0068
GO-2021-0068
Published: 14 Apr 2021Last Modified: 20 May 2024
Aliases:
Summary: Arbitrary code injection via the go command with cgo on Windows in cmd/go
Details: The go command may execute arbitrary code at build time when using cgo on Windows. This can be triggered by running go get on a malicious module, or any other time the code is built.
References: https://go.dev/cl/284783, https://go.googlesource.com/go/+/953d1feca9b21af075ad5fc8a3dad096d3ccc3a0, https://go.dev/issue/43783, https://groups.google.com/g/golang-announce/c/mperVMGa98w/m/yo5W5wnvAAAJ, https://go.dev/cl/284780, https://go.googlesource.com/go/+/46e2e2e9d99925bbf724b12693c6d3e27a95d6a0
Affected packages
Package
Name: toolchain
Purl: pkg:golang/toolchain
Affected ranges
Type: SEMVER
Events:
Introduced- 0
Fixed -1.14.14
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
