QID 995624
Date Published: 2023-10-25
QID 995624: GO (Go) Security Update for github.com/arduino/arduino-create-agent (GHSA-m5jc-r4gf-c6p8)
The vulnerability affects the endpoint /v2/pkgs/tools/installed and the way it handles plugin names supplied as user input. A user who has the ability to perform HTTP requests to the localhost interface, or is able to bypass the CORS configuration, can delete arbitrary files or folders belonging to the user that runs the Arduino Create Agent via a crafted HTTP POST request. Further details are available in the references.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-m5jc-r4gf-c6p8 for updates and patch information.
Vendor References
- GHSA-m5jc-r4gf-c6p8 -
github.com/advisories/GHSA-m5jc-r4gf-c6p8
CVEs related to QID 995624
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-m5jc-r4gf-c6p8 | github.com/arduino/arduino-create-agent |
|