PT-2023-9548 · Go+5 · Go+5

Hunter Wittenborn

·

Published

2023-08-08

·

Updated

2026-05-27

·

CVE-2023-24531

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Go (affected versions not specified)
Description The issue is related to the command go env which outputs a shell script containing the Go environment. However, go env does not sanitize the values, allowing for various bad behaviors when its output is executed as a shell script. This can include executing arbitrary commands or inserting new environment variables. The problem is considered relatively minor because an attacker who can set arbitrary environment variables on a system likely has better attack vectors.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

AZL-43104
AZL-43110
AZL-52719
AZL-79036
BDU:2024-08391
BIT-GOLANG-2023-24531
CVE-2023-24531
GO-2024-2962
USN-7061-1
USN-7109-1

Affected Products

Astra Linux
Debian
Go
Linuxmint
Red Os
Ubuntu