GO-2022-0190

Source
https://storage.googleapis.com/go-vulndb/ID/GO-2022-0190.json
Aliases
Published
2022-08-02T15:44:23Z
Modified
2022-08-19T22:21:47Z
Details

The "go get" command is vulnerable to directory traversal when executed with the import path of a malicious Go package which contains curly brace (both '{' and '}' characters).

Specifically, it is only vulnerable in GOPATH mode, but not in module mode (the distinction is documented at https://golang.org/cmd/go/#hdr-Moduleawarego_get). The attacker can cause an arbitrary filesystem write, which can lead to code execution.

References

Affected packages

Go / stdlib

stdlib

Affected ranges

Type
SEMVER
Events
Introduced
0
Fixed
1.10.6
Introduced
1.11.0
Fixed
1.11.3

Affected versions

Ecosystem specific

{
    "imports": [
        {
            "path": "cmd/go/internal/get",
            "symbols": [
                "downloadPackage"
            ]
        }
    ]
}

Database specific

{
    "url": "https://pkg.go.dev/vuln/GO-2022-0190"
}