Vulnerability Report: GO-2021-0068
standard library- CVE-2021-3115
- Affects: cmd/go
- Published: Apr 14, 2021
- Modified: May 20, 2024
The go command may execute arbitrary code at build time when using cgo on Windows. This can be triggered by running go get on a malicious module, or any other time the code is built.
Affected Packages
-
PathGo VersionsSymbols
-
before go1.14.14, from go1.15.0-0 before go1.15.7all symbols
Aliases
References
- https://go.dev/cl/284783
- https://go.googlesource.com/go/+/953d1feca9b21af075ad5fc8a3dad096d3ccc3a0
- https://go.dev/issue/43783
- https://groups.google.com/g/golang-announce/c/mperVMGa98w/m/yo5W5wnvAAAJ
- https://go.dev/cl/284780
- https://go.googlesource.com/go/+/46e2e2e9d99925bbf724b12693c6d3e27a95d6a0
- https://vuln.go.dev/ID/GO-2021-0068.json
Credits
- RyotaK
Feedback
See anything missing or incorrect?
Suggest an edit to this report.