PT-2023-9548 · Go+5 · Go+5
Hunter Wittenborn
·
Publicado
2023-08-08
·
Atualizado
2026-05-27
·
CVE-2023-24531
CVSS v2.0
10
Crítica
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Go (affected versions not specified)
Description
The issue is related to the command
go env which outputs a shell script containing the Go environment. However, go env does not sanitize the values, allowing for various bad behaviors when its output is executed as a shell script. This can include executing arbitrary commands or inserting new environment variables. The problem is considered relatively minor because an attacker who can set arbitrary environment variables on a system likely has better attack vectors.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Astra Linux
Debian
Go
Linuxmint
Red Os
Ubuntu