Go before 1.8.4 and 1.9.x before 1.9.1 allows "go get" remote command execution. Using custom domains, it is possible to arrange things so that example.com/pkg1 points to a Subversion repository but example.com/pkg1/pkg2 points to a Git repository. If the Subversion repository includes a Git checkout in its pkg2 directory and some other work is done to ensure the proper ordering of operations, "go get" can be tricked into reusing this Git checkout for the fetch of code from pkg2. If the Subversion repository's Git checkout has malicious commands in .git/hooks/, they will execute on the system running "go get."
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade go | Oct 25, 2017 | Oct 5, 2017 |
| Amazon Linux Ami 2 | — | Upgrade golang-docsUpgrade golang-miscUpgrade golang-binUpgrade golangUpgrade golang-srcUpgrade golang-tests | Apr 27, 2020 | Oct 5, 2017 |
| Amazon_linux | — | Upgrade golang | Nov 3, 2017 | Oct 5, 2017 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Oct 5, 2017 |
| Centos_linux | — | Upgrade golang-docsUpgrade golang-miscUpgrade golang-binUpgrade golang-testsUpgrade golangUpgrade golang-src | Aug 28, 2019 | Oct 5, 2017 |
| Debian | — | Upgrade golang-1.7Upgrade golang-1.8Upgrade golang | Feb 25, 2019 | Oct 5, 2017 |
| Gentoo Linux | — | Upgrade dev-lang/go. | Oct 30, 2017 | Oct 5, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade golang-binUpgrade golangUpgrade golang-src | Dec 4, 2017 | Oct 5, 2017 |
| Oracle Solaris | — | Upgrade system/library/gcc/gcc-c-runtime to version 9.2.0-11.4.21.0.1.69.0 on Solaris 11.4Upgrade developer/gcc/gcc-go-9 to version 9.2.0-11.4.21.0.1.69.0 on Solaris 11.4Upgrade system/library/gcc/gcc-gobjc-runtime to version 9.2.0-11.4.21.0.1.69.0 on Solaris 11.4Upgrade developer/gcc/gcc-go to version 9.2.0-11.4.21.0.1.69.0 on Solaris 11.4Upgrade developer/gcc-9 to version 9.2.0-11.4.21.0.1.69.0 on Solaris 11.4Upgrade system/library/gcc/gcc-go-runtime-9 to version 9.2.0-11.4.21.0.1.69.0 on Solaris 11.4Upgrade system/library/gcc/gcc-c-runtime-9 to version 9.2.0-11.4.21.0.1.69.0 on Solaris 11.4Upgrade developer/gcc/gcc-gfortran to version 9.2.0-11.4.21.0.1.69.0 on Solaris 11.4Upgrade developer/gcc/gcc-c++ to version 9.2.0-11.4.21.0.1.69.0 on Solaris 11.4Upgrade developer/gcc/gcc-common-9 to version 9.2.0-11.4.21.0.1.69.0 on Solaris 11.4Upgrade system/library/gcc/gcc-go-runtime to version 9.2.0-11.4.21.0.1.69.0 on Solaris 11.4Upgrade system/library/gcc/gcc-gfortran-runtime to version 9.2.0-11.4.21.0.1.69.0 on Solaris 11.4Upgrade system/library/gcc/gcc-gfortran-runtime-9 to version 9.2.0-11.4.21.0.1.69.0 on Solaris 11.4Upgrade developer/gcc/gcc-gfortran-9 to version 9.2.0-11.4.21.0.1.69.0 on Solaris 11.4Upgrade system/library/gcc/gcc-runtime to version 9.2.0-11.4.21.0.1.69.0 on Solaris 11.4Upgrade developer/gcc/gcc-gobjc-9 to version 9.2.0-11.4.21.0.1.69.0 on Solaris 11.4Upgrade system/library/gcc/gcc-gobjc-runtime-9 to version 9.2.0-11.4.21.0.1.69.0 on Solaris 11.4Upgrade developer/gcc to version 9.2.0-11.4.21.0.1.69.0 on Solaris 11.4Upgrade developer/gcc/gcc-gobjc to version 9.2.0-11.4.21.0.1.69.0 on Solaris 11.4Upgrade developer/gcc/gcc-c-9 to version 9.2.0-11.4.21.0.1.69.0 on Solaris 11.4Upgrade system/library/gcc/gcc-runtime-9 to version 9.2.0-11.4.21.0.1.69.0 on Solaris 11.4 | Jan 19, 2021 | Oct 5, 2017 |
| Redhat_linux | — | Upgrade golang-miscUpgrade golang-srcUpgrade golangUpgrade golang-binUpgrade golang-docsUpgrade golang-tests | Apr 11, 2018 | Oct 5, 2017 |
| Suse | — | Upgrade go | Aug 9, 2024 | Oct 5, 2017 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Oct 5, 2017 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Oct 5, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub