Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-3115


Go before 1.14.14 and 1.15.x before 1.15.7 on Windows is vulnerable to Command Injection and remote code execution when using the "go get" command to fetch modules that make use of cgo (for example, cgo can execute a gcc program from an untrusted download).


Published

2021-01-26T18:16:27.630

Last Modified

2024-11-21T06:20:54.910

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:H/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: HIGH
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

4.9

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-427

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application golang go < 1.14.14 Yes
Application golang go < 1.15.7 Yes
Operating System microsoft windows - No
Operating System fedoraproject fedora 33 Yes
Application netapp cloud_insights_telegraf_agent - Yes
Application netapp storagegrid - Yes

References