/
DirectorySecurity Advisories
Sign In
Security Advisories

CVE-2023-39320

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2023-39320

CGA ID

CGA-8j4j-qxh6-9m2p

Severity

9.8

Critical

CVSS V3

Description

The go.mod toolchain directive, introduced in Go 1.21, can be leveraged to execute scripts and binaries relative to the root of the module when the "go" command was executed within the module. This applies to modules downloaded using the "go" command from the module proxy, as well as modules downloaded directly using VCS software.

References

Affected packages


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images