CVE-2018-7187
EPSS 7.6%golang-1.7 - security update
發布日:2022/8/9修改日:2026/3/9
描述
The "go get" command is vulnerable to remote code execution. When the -insecure command-line option is used, "go get" does not validate the import path (get/vcs.go only checks for "://" anywhere in the string), which allows remote attackers to execute arbitrary OS commands via a crafted web site.
受影響套件(3)
- Debian/golangfrom 0, < 2:1.0.2-1.1+deb7u3
- Debian/golang-1.7from 0, < 1.7.4-2+deb9u1
- Go/toolchainfrom 0, < 1.9.5, >= 1.10.0-0, < 1.10.1