Description
Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercurial (hg) installed, downloading modules from non-standard sources (e.g., custom domains) can cause unexpected code execution due to how external VCS commands are constructed. This issue can also be triggered by providing a malicious version string to the toolchain. On systems with Git installed, downloading and building modules with malicious version strings can allow an attacker to write to arbitrary files on the filesystem. This can only be triggered by explicitly providing the malicious version strings to the toolchain and does not affect usage of @latest or bare module paths.
Details
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| golang-1.10 | — | — |
| golang-1.13 | — | — |
| golang-1.14 | — | — |
| golang-1.16 | — | — |
| golang-1.17 | — | — |
| golang-1.18 | — | — |
| golang-1.20 | — | — |
| golang-1.21 | — | — |
| golang-1.22 | — | — |
| golang-1.23 | — | — |
| golang-1.24 | — | — |
| golang-1.25 | — | — |
| golang-1.6 | — | — |
| golang-1.8 | — | — |
| golang-1.9 | — | — |
References
Similar Threats
- Unknown UBUNTU-CVE-2023-24531
- Unknown UBUNTU-CVE-2023-24534
- Unknown UBUNTU-CVE-2023-24532
- Unknown UBUNTU-CVE-2022-41723
- Unknown UBUNTU-CVE-2022-41725
Free Vulnerability Check
Is your WordPress site affected?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.