Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:34198
HistoryFeb 14, 2022 - 8:44 a.m.

Remote Code Execution (RCE)

2022-02-1408:44:04
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
19
remote code execution
golang
github
elliptic.go
vulnerability
attacker
software
field element

EPSS

0.006

Percentile

77.8%

github.com/golang/go is vulnerable to remote code execution. The vulnerability exists in IsOnCurve function of elliptic.go because of invalid representations of a field element which allows an attacker to inject and execute codes.