Vulnerability Description
In Go Doc Dot Org (gddo) through 2018-06-27, an attacker could use specially crafted <go-import> tags in packages being fetched by gddo to cause a directory traversal and remote code execution.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Godoc | Go Doc Dot Org | <= 2018-06-27 |
Related Weaknesses (CWE)
References
- https://github.com/golang/gddo/commit/daffe1f90ec57f8ed69464f9094753fc6452e983PatchThird Party Advisory
- https://groups.google.com/forum/#%21msg/golang-announce/4rpTbfzYB1k/no6MEwlQAwAJ
- https://github.com/golang/gddo/commit/daffe1f90ec57f8ed69464f9094753fc6452e983PatchThird Party Advisory
- https://groups.google.com/forum/#%21msg/golang-announce/4rpTbfzYB1k/no6MEwlQAwAJ
FAQ
What is CVE-2018-12976?
CVE-2018-12976 is a vulnerability with a CVSS score of 9.8 (CRITICAL). In Go Doc Dot Org (gddo) through 2018-06-27, an attacker could use specially crafted <go-import> tags in packages being fetched by gddo to cause a directory traversal and remote code execution.
How severe is CVE-2018-12976?
CVE-2018-12976 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-12976?
Check the references section above for vendor advisories and patch information. Affected products include: Godoc Go Doc Dot Org.