Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time via a malicious unquoted symbol name in a linked object file.
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Go | Golang | * | 1.14.12 (excluding) |
Go | Golang | 1.15 (including) | 1.15.5 (excluding) |
Openshift Serveless 1.12 | RedHat | openshift-serverless-1/client-kn-rhel8:0.18.4-2 | * |
Openshift Serveless 1.12 | RedHat | openshift-serverless-1/eventing-apiserver-receive-adapter-rhel8:0.18.6-2 | * |
Openshift Serveless 1.12 | RedHat | openshift-serverless-1/eventing-controller-rhel8:0.18.6-2 | * |
Openshift Serveless 1.12 | RedHat | openshift-serverless-1/eventing-in-memory-channel-controller-rhel8:0.18.6-2 | * |
Openshift Serveless 1.12 | RedHat | openshift-serverless-1/eventing-in-memory-channel-dispatcher-rhel8:0.18.6-2 | * |
Openshift Serveless 1.12 | RedHat | openshift-serverless-1/eventing-mtbroker-filter-rhel8:0.18.6-2 | * |
Openshift Serveless 1.12 | RedHat | openshift-serverless-1/eventing-mtbroker-ingress-rhel8:0.18.6-2 | * |
Openshift Serveless 1.12 | RedHat | openshift-serverless-1/eventing-mtchannel-broker-rhel8:0.18.6-2 | * |
Openshift Serveless 1.12 | RedHat | openshift-serverless-1/eventing-mtping-rhel8:0.18.6-2 | * |
Openshift Serveless 1.12 | RedHat | openshift-serverless-1/eventing-storage-version-migration-rhel8:0.18.6-2 | * |
Openshift Serveless 1.12 | RedHat | openshift-serverless-1/eventing-sugar-controller-rhel8:0.18.6-2 | * |
Openshift Serveless 1.12 | RedHat | openshift-serverless-1/eventing-webhook-rhel8:0.18.6-2 | * |
Openshift Serveless 1.12 | RedHat | openshift-serverless-1/ingress-rhel8-operator:1.12.0-2 | * |
Openshift Serveless 1.12 | RedHat | openshift-serverless-1/knative-rhel8-operator:1.12.0-3 | * |
Openshift Serveless 1.12 | RedHat | openshift-serverless-1/kn-cli-artifacts-rhel8:0.18.4-2 | * |
Openshift Serveless 1.12 | RedHat | openshift-serverless-1/kourier-control-rhel8:0.18.0-2 | * |
Openshift Serveless 1.12 | RedHat | openshift-serverless-1/serverless-operator-bundle:1.12.0-5 | * |
Openshift Serveless 1.12 | RedHat | openshift-serverless-1/serverless-rhel8-operator:1.12.0-4 | * |
Openshift Serveless 1.12 | RedHat | openshift-serverless-1/serving-activator-rhel8:0.18.2-3 | * |
Openshift Serveless 1.12 | RedHat | openshift-serverless-1/serving-autoscaler-hpa-rhel8:0.18.2-3 | * |
Openshift Serveless 1.12 | RedHat | openshift-serverless-1/serving-autoscaler-rhel8:0.18.2-3 | * |
Openshift Serveless 1.12 | RedHat | openshift-serverless-1/serving-controller-rhel8:0.18.2-3 | * |
Openshift Serveless 1.12 | RedHat | openshift-serverless-1/serving-queue-rhel8:0.18.2-3 | * |
Openshift Serveless 1.12 | RedHat | openshift-serverless-1/serving-storage-version-migration-rhel8:0.18.2-3 | * |
Openshift Serveless 1.12 | RedHat | openshift-serverless-1/serving-webhook-rhel8:0.18.2-3 | * |
Openshift Serveless 1.12 | RedHat | openshift-serverless-1/svls-must-gather-rhel8:1.12.0-2 | * |
Openshift Serverless 1 on RHEL 8 | RedHat | openshift-serverless-clients-0:0.18.4-2.el8 | * |
Red Hat Developer Tools | RedHat | go-toolset-1.14-0:1.14.12-1.el7_9 | * |
Red Hat Developer Tools | RedHat | go-toolset-1.14-golang-0:1.14.12-1.el7_9 | * |
Red Hat Enterprise Linux 8 | RedHat | go-toolset:rhel8-8030020201118084734.58e1918e | * |
Golang | Ubuntu | trusty | * |
Golang-1.10 | Ubuntu | bionic | * |
Golang-1.10 | Ubuntu | esm-infra-legacy/trusty | * |
Golang-1.10 | Ubuntu | esm-infra/bionic | * |
Golang-1.10 | Ubuntu | esm-infra/xenial | * |
Golang-1.10 | Ubuntu | trusty | * |
Golang-1.10 | Ubuntu | trusty/esm | * |
Golang-1.10 | Ubuntu | xenial | * |
Golang-1.13 | Ubuntu | bionic | * |
Golang-1.13 | Ubuntu | esm-apps/bionic | * |
Golang-1.13 | Ubuntu | esm-apps/jammy | * |
Golang-1.13 | Ubuntu | esm-apps/xenial | * |
Golang-1.13 | Ubuntu | esm-infra/focal | * |
Golang-1.13 | Ubuntu | focal | * |
Golang-1.13 | Ubuntu | groovy | * |
Golang-1.13 | Ubuntu | hirsute | * |
Golang-1.13 | Ubuntu | impish | * |
Golang-1.13 | Ubuntu | jammy | * |
Golang-1.13 | Ubuntu | kinetic | * |
Golang-1.13 | Ubuntu | xenial | * |
Golang-1.14 | Ubuntu | esm-infra/focal | * |
Golang-1.14 | Ubuntu | focal | * |
Golang-1.14 | Ubuntu | groovy | * |
Golang-1.14 | Ubuntu | hirsute | * |
Golang-1.14 | Ubuntu | upstream | * |
Golang-1.15 | Ubuntu | groovy | * |
Golang-1.15 | Ubuntu | hirsute | * |
Golang-1.15 | Ubuntu | impish | * |
Golang-1.15 | Ubuntu | upstream | * |
Golang-1.6 | Ubuntu | trusty | * |
Golang-1.6 | Ubuntu | xenial | * |
Golang-1.8 | Ubuntu | bionic | * |
Golang-1.8 | Ubuntu | esm-apps/bionic | * |
Golang-1.9 | Ubuntu | bionic | * |
Golang-1.9 | Ubuntu | esm-apps/bionic | * |