QID 995621

Date Published: 2023-10-25

QID 995621: GO (Go) Security Update for github.com/arduino/arduino-create-agent (GHSA-mjq6-pv9c-qppq)

The vulnerability affects the endpoint /v2/pkgs/tools/installed and the way it handles plugin names supplied as user input. A user who has the ability to perform HTTP requests to the localhost interface, or is able to bypass the CORS configuration, can delete arbitrary files or folders belonging to the user that runs the Arduino Create Agent via a crafted HTTP DELETE request. Further details are available in the references.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 7.1 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-mjq6-pv9c-qppq for updates and patch information.
    Vendor References

    CVEs related to QID 995621

    Software Advisories
    Advisory ID Software Component Link
    GHSA-mjq6-pv9c-qppq github.com/arduino/arduino-create-agent URL Logo github.com/advisories/GHSA-mjq6-pv9c-qppq