Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:12699
HistoryJan 15, 2019 - 9:20 a.m.

Remote Code Execution (RCE)

2019-01-1509:20:33
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12

EPSS

0.055

Percentile

93.3%

github.com/golang/go is vulnerable to remote code execution (RCE). If custom domains are used, a malicious user can set a domain example.com/proj1 to point to a subversion repository and another domain example.com/proj1/proj2 to point to a git repository. When the go get command is run, arbitrary commands in the subversion’s .git/hooks/ is executed on the system that ran the command.