blob: edf8ab43d50c63970b91b62c3d115bebd21fc46d [file] [log] [blame]
Copyright 2023 The Go Authors. All rights reserved.
Use of this source code is governed by a BSD-style
license that can be found in the LICENSE file.
Expected output of TestCVE5ToReport/CVE-2021-3115.
-- CVE-2021-3115 --
id: PLACEHOLDER-ID
modules:
- module: cmd
packages:
- package: cmd/go
description: |
Go before 1.14.14 and 1.15.x before 1.15.7 on Windows is vulnerable to Command Injection and remote code execution when using the "go get" command to fetch modules that make use of cgo (for example, cgo can execute a gcc program from an untrusted download).
cves:
- CVE-2021-3115
references:
- web: https://groups.google.com/g/golang-announce/c/mperVMGa98w
- web: https://blog.golang.org/path-security
- web: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YWAYJGXWC232SG3UR3TR574E6BP3OSQQ/
- web: https://security.netapp.com/advisory/ntap-20210219-0001/
- web: https://security.gentoo.org/glsa/202208-02