PT-2023-9548 · Go+5 · Go+5
Hunter Wittenborn
·
Published
2023-08-08
·
Updated
2026-05-27
·
CVE-2023-24531
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Go (affected versions not specified)
Description
The issue is related to the command
go env which outputs a shell script containing the Go environment. However, go env does not sanitize the values, allowing for various bad behaviors when its output is executed as a shell script. This can include executing arbitrary commands or inserting new environment variables. The problem is considered relatively minor because an attacker who can set arbitrary environment variables on a system likely has better attack vectors.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Debian
Go
Linuxmint
Red Os
Ubuntu