此前,在一个定义了虚假的 golang.org/fips140 模块并配置了由攻击者控制的恶意 GOMODPROXY 的恶意 Go 项目中,用户若连接到该代理,可能会被提供任意模块以替代预期的依赖模块。现在,我们解压受信任的 golang.org/fips140 打包模块的 ziphash,并在 GOMODCACHE 中构建其对应的条目,从而使得该模块能够通过工具链的验证。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Go toolchain | cmd/go | 0 ~ 1.26.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet