HIGH · 7.5

CVE-2021-3115

Go before 1.14.14 and 1.15.x before 1.15.7 on Windows is vulnerable to Command Injection and remote code execution when using the "go get" command to fetch modules that make use of cgo (for example, c...

Vulnerability Description

Go before 1.14.14 and 1.15.x before 1.15.7 on Windows is vulnerable to Command Injection and remote code execution when using the "go get" command to fetch modules that make use of cgo (for example, cgo can execute a gcc program from an untrusted download).

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
GolangGo< 1.14.14
MicrosoftWindows-
FedoraprojectFedora33
NetappCloud Insights Telegraf Agent-
NetappStoragegrid-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-3115?

CVE-2021-3115 is a vulnerability with a CVSS score of 7.5 (HIGH). Go before 1.14.14 and 1.15.x before 1.15.7 on Windows is vulnerable to Command Injection and remote code execution when using the "go get" command to fetch modules that make use of cgo (for example, c...

How severe is CVE-2021-3115?

CVE-2021-3115 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-3115?

Check the references section above for vendor advisories and patch information. Affected products include: Golang Go, Microsoft Windows, Fedoraproject Fedora, Netapp Cloud Insights Telegraf Agent, Netapp Storagegrid.