GO-2023-2042
Dashboard / Vulnerabilities / GO-2023-2042
Summary: Arbitrary code execution via go.mod toolchain directive in cmd/go
Details: The go.mod toolchain directive, introduced in Go 1.21, can be leveraged to execute scripts and binaries relative to the root of the module when the "go" command was executed within the module. This applies to modules downloaded using the "go" command from the module proxy, as well as modules downloaded directly using VCS software.
References: https://go.dev/issue/62198, https://go.dev/cl/526158, https://groups.google.com/g/golang-dev/c/2C5vbR-UNkI/m/L1hdrPhfBAAJ
Affected packages
Package
Name: toolchain
Purl: pkg:golang/toolchain
Affected ranges
Type: SEMVER
Events:
Introduced- 1.21.0-0
Fixed -1.21.1
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
