[GO-2022-0532] Empty Cmd.Path can trigger unintended binary in os/exec on Windows

Severity High
Affected Packages 2
Fixed Packages 2
CVEs 1

On Windows, executing Cmd.Run, Cmd.Start, Cmd.Output, or Cmd.CombinedOutput when
Cmd.Path is unset will unintentionally trigger execution of any binaries in the
working directory named either "..com" or "..exe".

Package Affected Version
pkg:golang/os/exec >= 1.18.2, < 1.17.11
pkg:golang/os/exec >= 1.18.2, < 1.18.3
Package Fixed Version
pkg:golang/os/exec = 1.17.11
pkg:golang/os/exec = 1.18.3
ID
GO-2022-0532
Severity
high
Severity from
CVE-2022-30580
URL
https://pkg.go.dev/vuln/GO-2022-0532
Published
2022-08-12T17:19:52
(2 years ago)
Modified
2024-07-17T19:54:18
(2 months ago)
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Fixed pkg:golang/os/exec os exec = 1.17.11
Affected pkg:golang/os/exec os exec >= 1.18.2 < 1.17.11
Fixed pkg:golang/os/exec os exec = 1.18.3
Affected pkg:golang/os/exec os exec >= 1.18.2 < 1.18.3
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...