CVE-2021-3115
Summary
| CVE | CVE-2021-3115 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-01-26 18:16:00 UTC |
| Updated | 2023-11-07 03:37:00 UTC |
| Description | Go before 1.14.14 and 1.15.x before 1.15.7 on Windows is vulnerable to Command Injection and remote code execution when using the "go get" command to fetch modules that make use of cgo (for example, cgo can execute a gcc program from an untrusted download). |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [security] Go 1.15.7 and Go 1.14.14 are released |
CONFIRM |
groups.google.com |
Release Notes, Third Party Advisory |
| [SECURITY] Fedora 33 Update: golang-1.15.7-1.fc33 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Mailing List, Third Party Advisory |
| February 2021 Golang Vulnerabilities in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
Third Party Advisory |
| Command PATH security in Go - The Go Blog |
CONFIRM |
blog.golang.org |
Vendor Advisory |
| [SECURITY] Fedora 33 Update: golang-1.15.7-1.fc33 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Go: Multiple Vulnerabilities (GLSA 202208-02) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159209 Oracle Enterprise Linux Security Update for go-toolset:ol8 (ELSA-2021-1746)
- 179936 Debian Security Update for golang-1.15 (CVE-2021-3115)
- 239312 Red Hat Update for go-toolset:rhel8 (RHSA-2021:1746)
- 352297 Amazon Linux Security Update for golang: AL2012-2021-340
- 375393 Go Command Injection and Remote Code Execution Vulnerability
- 501575 Alpine Linux Security Update for go
- 690411 Free Berkeley Software Distribution (FreeBSD) Security Update for go (6a4805d5-5aaf-11eb-a21d-79f5bc5ef6a9)
- 710584 Gentoo Linux Go Multiple Vulnerabilities (GLSA 202208-02)
- 750384 OpenSUSE Security Update for go1.14 (openSUSE-SU-2021:0194-1)
- 750385 OpenSUSE Security Update for go1.14 (openSUSE-SU-2021:0190-1)
- 750387 OpenSUSE Security Update for go1.15 (openSUSE-SU-2021:0192-1)
- 940200 AlmaLinux Security Update for go-toolset:rhel8 (ALSA-2021:1746)
- 960773 Rocky Linux Security Update for go-toolset:rhel8 (RLSA-2021:1746)