blob: dbbd7b4086a802db00874399e9e54bd0180deee9 [file] [log] [blame]
id: GO-2024-2993
modules:
- module: github.com/bishopfox/sliver
versions:
- introduced: 1.5.40
non_go_versions:
- fixed: 1.6.0
vulnerable_at: 1.5.42
summary: Sliver Allows Authenticated Operator-to-Server Remote Code Execution in github.com/bishopfox/sliver
cves:
- CVE-2024-41111
ghsas:
- GHSA-hc5w-gxxr-w8x8
references:
- advisory: https://github.com/BishopFox/sliver/security/advisories/GHSA-hc5w-gxxr-w8x8
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2024-41111
- web: https://github.com/BishopFox/sliver/commit/0deaee625d14c6f05f63c86e5c3b7ae623a1138f
- web: https://github.com/BishopFox/sliver/commit/5016fb8d7cdff38c79e22e8293e58300f8d3bd57
- web: https://github.com/BishopFox/sliver/commit/d8ff64222dc69d931197d0bbae3fba11dbe17533
- web: https://github.com/BishopFox/sliver/issues/65
- web: https://github.com/BishopFox/sliver/pull/1281
- web: https://sliver.sh/docs?name=Multi-player+Mode
source:
id: GHSA-hc5w-gxxr-w8x8
created: 2024-08-16T16:55:45.510461-04:00
review_status: UNREVIEWED