Total vulnerabilities in the database
The "go get" implementation in Go 1.9.4, when the -insecure command-line option is used, does not validate the import path (get/vcs.go only checks for "://" anywhere in the string), which allows remote attackers to execute arbitrary OS commands via a crafted web site.
Software | From | Fixed in |
---|---|---|
golang / go | - | 1.9.5 |
golang / go | 1.10 | 1.10.1 |
debian / debian_linux | 7.0 | 7.0.x |
debian / debian_linux | 9.0 | 9.0.x |