The go.mod toolchain directive, introduced in Go 1.21, can be leveraged to execute scripts and binaries relative to the root of the module when the "go" command was executed within the module. This applies to modules downloaded using the "go" command from the module proxy, as well as modules downloaded directly using VCS software.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade go | Aug 22, 2024 | Sep 8, 2023 |
| Freebsd | — | Upgrade go120Upgrade go121 | Sep 8, 2023 | Sep 7, 2023 |
| Gentoo Linux | — | Upgrade dev-lang/go. | Nov 27, 2023 | Sep 8, 2023 |
| Splunk | — | Upgrade Splunk Enterprise to version 9.2.3Upgrade Splunk Enterprise to version 9.1.6Upgrade Splunk Enterprise to version 9.3.1 | Jul 30, 2026 | Sep 8, 2023 |
| Suse | — | Upgrade go1.21Upgrade go1.21-docUpgrade go1.21-openssl-docUpgrade go1.21-openssl-raceUpgrade go1.21-opensslUpgrade go1.21-race | Sep 21, 2023 | Sep 8, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub