Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The "go get" implementation in Go 1.9.4, when the -insecure command-line option is used, does not validate the import path (get/vcs.go only checks for "://" anywhere in the string), which allows remote attackers to execute arbitrary OS commands via a crafted web site.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Google Go 输入验证错误漏洞
Vulnerability Description
Google Go是美国谷歌(Google)公司的一种针对多处理器系统应用程序的编程进行了优化的编程语言。 Google Go 1.9.4版本中的‘go get’的实现存在输入验证漏洞,该漏洞源于在使用-insecure命令行选项时,程序没有校验输入路径。远程攻击者可借助特制的网站利用该漏洞执行任意操作系统命令。
CVSS Information
N/A
Vulnerability Type
N/A