PT-2022-19706 · Unknown · Kardianos Service Package

Ghost

·

Published

2022-04-22

·

Updated

2024-08-03

·

CVE-2022-29583

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions kardianos service package for Go (affected versions not specified)
Description The issue is related to the service windows.go file in the kardianos service package for Go, which omits quoting that is sometimes needed for the execution of a Windows service executable from the intended directory. The validity of this issue has been questioned, and the reporter has requested that it be disputed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Untrusted Search Path

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2022-29583
GHSA-XM99-6PV5-Q363

Affected Products

Kardianos Service Package