CVE-2023-29402
Code injection via go command with cgo in cmd/go
9.8
CRITICAL
CVSS 3.1
EPSS 0.13%
Description
The go command may generate unexpected code at build time when using cgo. This may result in unexpected behavior when running a go program which uses cgo. This may occur when running an untrusted module which contains directories with newline characters in their names. Modules which are retrieved using the go command, i.e. via "go get", are not affected (modules retrieved using GOPATH-mode, i.e. GO111MODULE=off, may be affected).
How to fix CVE-2023-29402
To remediate CVE-2023-29402, upgrade the affected package to a fixed version below.
- —upgrade to 1.19.10 or later
- —no fix listed
- —no fix listed
- —upgrade to 1.19.10 or later
Is CVE-2023-29402 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (4)
- from 0, < 1.19.10, >= 1.20.0, < 1.20.5
- from 0
- from 0
- from 0, < 1.19.10, >= 1.20.0-0, < 1.20.5
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |