Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:5240
HistoryOct 06, 2017 - 1:57 a.m.

Remote Code Execution (RCE)

2017-10-0601:57:43
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
17

EPSS

0.055

Percentile

93.3%

github.com/golang/go is vulnerable to remote code execution (RCE). If custom domains are used, a malicious user can set a domain example.com/proj1 to point to a subversion repository and another domain example.com/proj1/proj2 to point to a git repository. When the go get command is run, arbitrary commands in the subversion’s .git/hooks/ is executed on the system that ran the command.