CVE-2018-7187

EPSS 7.6%

golang-1.7 - security update

發布日:2022/8/9修改日:2026/3/9

描述

The "go get" command is vulnerable to remote code execution. When the -insecure command-line option is used, "go get" does not validate the import path (get/vcs.go only checks for "://" anywhere in the string), which allows remote attackers to execute arbitrary OS commands via a crafted web site.

受影響套件(3)

參考連結(4)