CVE-2022-30580

Code injection in Cmd.Start in os/exec before Go 1.17.11 and Go 1.18.3 allows execution of any binaries in the working directory named either "..com" or "..exe" by calling Cmd.Run, Cmd.Start, Cmd.Output, or Cmd.CombinedOutput when Cmd.Path is unset.
References
Link Resource
https://go.dev/cl/403759 Vendor Advisory
https://go.dev/issue/52574 Issue Tracking Third Party Advisory
https://go.googlesource.com/go/+/960ffa98ce73ef2c2060c84c7ac28d37a83f345e Mailing List Patch Vendor Advisory
https://groups.google.com/g/golang-announce/c/TzIC9-t8Ytg/m/IWz5T6x7AAAJ Mailing List Third Party Advisory
https://pkg.go.dev/vuln/GO-2022-0532 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*
cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2022-08-10 20:15

Updated : 2024-02-28 19:29


NVD link : CVE-2022-30580

Mitre link : CVE-2022-30580

CVE.ORG link : CVE-2022-30580


JSON object : View

Products Affected

golang

  • go
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')