golang: "go get" vulnerable to directory traversal via malicious package
Published Dec 14, 2018
8.1
HIGHCVSS 3.1
EPSS 5.04%
Description
In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to directory traversal when executed with the import path of a malicious Go package which contains curly braces (both '{' and '}' characters). Specifically, it is only vulnerable in GOPATH mode, but not in module mode (the distinction is documented at https://golang.org/cmd/go/#hdr-Module_aware_go_get). The attacker can cause an arbitrary filesystem write, which can lead to code execution.
Affected products
- Vendor n/a Product Golang Defaultn/a
- Version 1.10.6StatusaffectedConstraints-
- Version 1.11.3StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| n/a | Golang | n/a |
|
Configuration 2
- 15.0
- 15.0
- 15.1
- 42.3
- 12
Configuration 3
- 9.0
No data.
Red Hat Ceph Storage 2
golang
Will not fix
Red Hat Ceph Storage 3
golang
Will not fix
Red Hat Enterprise Linux 7
golang
Will not fix
Red Hat Enterprise Linux 8
go-toolset:rhel8/golang
Not affected
Red Hat OpenStack Platform 8 (Liberty) Operational Tools
golang
Will not fix
Red Hat OpenStack Platform 9 (Mitaka) Operational Tools
golang
Will not fix
Red Hat Storage 3
golang
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ceph Storage 2 | golang | Will not fix | n/a |
| Red Hat Ceph Storage 3 | golang | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | golang | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | go-toolset:rhel8/golang | Not affected | n/a |
| Red Hat OpenStack Platform 8 (Liberty) Operational Tools | golang | Will not fix | n/a |
| Red Hat OpenStack Platform 9 (Mitaka) Operational Tools | golang | Will not fix | n/a |
| Red Hat Storage 3 | golang | Will not fix | n/a |
toolchain
Go
Introduced 0 Fixed 1.10.6toolchain
Go
Introduced 1.11.0-0 Fixed 1.11.3
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | toolchain | 0 | 1.10.6 |
| Go | toolchain | 1.11.0-0 | 1.11.3 |
Remediation
Red Hat statement
This issue affects the version of golang package in Red Hat Enterprise Linux 7. The golang package, previously available in the Optional channel, will no longer receive updates in Red Hat Enterprise Linux 7. Developers are encouraged to use the Go Toolset instead, which is available through the Red Hat Developer program. https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/7.6_release_notes/chap-red_hat_enterprise_linux-7.6_release_notes-deprecated_functionality_in_rhel7#idm139716309923696
References (17)
- http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00044.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00060.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00011.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00015.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00010.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00041.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/106228 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2018-16874 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1657564 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16874 x_refsource_CONFIRMIssue TrackingThird Party Advisory
- https://groups.google.com/forum/?pli=1#!topic/golang-announce/Kw31K8G7Fi0
- https://groups.google.com/forum/?pli=1#%21topic/golang-announce/Kw31K8G7Fi0 x_refsource_MISC
- https://lists.debian.org/debian-lts-announce/2021/03/msg00014.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/03/msg00015.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-16874
- https://security.gentoo.org/glsa/201812-09 vendor-advisoryx_refsource_GENTOOMitigationThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2018-16874
Change history (0)
No recorded changes yet.