Vulnerability Name:

CVE-2018-7187 (CCN-139247)

Assigned:2018-02-16
Published:2018-02-16
Updated:2022-08-16
Summary:The "go get" implementation in Go 1.9.4, when the -insecure command-line option is used, does not validate the import path (get/vcs.go only checks for "://" anywhere in the string), which allows remote attackers to execute arbitrary OS commands via a crafted web site.
CVSS v3 Severity:8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
7.7 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
8.8 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
7.7 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
9.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-78
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2018-7187

Source: XF
Type: UNKNOWN
go-cve20187187-cmd-exec(139247)

Source: MISC
Type: Third Party Advisory
https://gist.github.com/SLAYEROWNER/b2a358f13ab267f2e9543bb9f9320ffc

Source: CCN
Type: Go GIT Repository
cmd/go: arbitrary command execution via VCS path #23867

Source: CONFIRM
Type: Exploit, Issue Tracking, Third Party Advisory
https://github.com/golang/go/issues/23867

Source: MLIST
Type: Mailing List, Third Party Advisory
[debian-lts-announce] 20180225 [SECURITY] [DLA 1294-1] golang security update

Source: GENTOO
Type: Third Party Advisory
GLSA-201804-12

Source: DEBIAN
Type: Third Party Advisory
DSA-4379

Source: DEBIAN
Type: Third Party Advisory
DSA-4380

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2018-7187

Vulnerable Configuration:Configuration 1:
  • cpe:/a:golang:go:*:*:*:*:*:*:*:* (Version < 1.9.5)
  • OR cpe:/a:golang:go:*:*:*:*:*:*:*:* (Version >= 1.10 and < 1.10.1)

  • Configuration 2:
  • cpe:/o:debian:debian_linux:7.0:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:9.0:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:golang:go:1.9.4:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20187187
    V
    CVE-2018-7187
    2023-06-22
    oval:org.opensuse.security:def:8012
    P
    go-1.19-150000.3.26.1 on GA media (Moderate)
    2023-06-20
    oval:org.opensuse.security:def:3161
    P
    libcares2-1.9.1-9.4.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3149
    P
    libXvMC1-1.0.8-7.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:112327
    P
    go-1.17-1.1 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:112344
    P
    go1.9-1.9.7-11.2 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:49457
    P
    Security update for nodejs14 (Important)
    2021-12-02
    oval:org.opensuse.security:def:105859
    P
    Security update for java-11-openjdk (Important)
    2021-11-16
    oval:org.opensuse.security:def:105848
    P
    go-1.17-1.1 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:2424
    P
    python2-keystoneclient-3.17.0-4.3.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:2420
    P
    postgresql-test-13-8.30 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:2430
    P
    sane-backends-32bit-1.0.32-6.6.2 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:1915
    P
    dom4j-1.6.1-10.12 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:1901
    P
    apache-pdfbox-1.8.16-1.68 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:1936
    P
    nasm-2.14.02-3.4.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:1917
    P
    gdb-10.1-8.24.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:1906
    P
    bsh2-2.0.0.b6-10.65 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:1941
    P
    pam-devel-32bit-1.3.0-6.29.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:1946
    P
    perl-Net-Libproxy-0.4.15-12.72 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:1923
    P
    graphviz-perl-2.40.1-6.6.8 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:1948
    P
    perl-YAML-LibYAML-0.69-3.3.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:51594
    P
    Security update for the Linux Kernel (Live Patch 37 for SLE 12 SP3) (Important)
    2021-06-18
    oval:org.opensuse.security:def:48413
    P
    evince-3.20.1-5.66 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:2471
    P
    pulseaudio-module-bluetooth-11.1-4.31 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48752
    P
    libzmq3-4.0.4-13.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48938
    P
    libpcrecpp0-32bit-8.39-8.3.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:2456
    P
    libgadu-devel-1.12.2-1.44 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48429
    P
    glibc-2.22-49.16 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48412
    P
    eog-3.20.4-7.7 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48893
    P
    bash-lang-4.3-83.15.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48956
    P
    libyaml-cpp0_5-0.5.3-3.3.2 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48937
    P
    libosip2-3.5.0-20.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:2462
    P
    libpurple-2.13.0-3.35 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48554
    P
    libssh2-1-1.4.3-19.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:2442
    P
    colord-1.4.2-1.37 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:51532
    P
    Security update for the Linux Kernel (Live Patch 37 for SLE 12 SP3) (Important)
    2021-04-07
    oval:org.opensuse.security:def:49083
    P
    Security update for salt (Critical)
    2021-02-26
    oval:org.opensuse.security:def:2501
    P
    libpskc-devel-2.6.2-1.15 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:48987
    P
    gd-32bit-2.1.0-24.12.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2509
    P
    openconnect-7.08-4.26 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2511
    P
    pulseaudio-module-bluetooth-11.1-4.31 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2495
    P
    libgadu-devel-1.12.2-1.44 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:1897
    P
    zlib-devel-32bit-1.2.11-3.12.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:1895
    P
    subversion-bash-completion-1.10.6-3.6.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2586
    P
    Security update for mariadb (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:2596
    P
    Security update for containerd, docker and go (Important)
    2020-12-02
    oval:org.opensuse.security:def:25097
    P
    Security update for curl (Important)
    2020-12-01
    oval:org.opensuse.security:def:25596
    P
    Security update for xorg-x11-server (Important)
    2020-12-01
    oval:org.opensuse.security:def:26433
    P
    Security update for MozillaThunderbird (Critical)
    2020-12-01
    oval:org.opensuse.security:def:49620
    P
    fetchmailconf on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49927
    P
    python2-pywbem on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25362
    P
    Security update for mailman (Important)
    2020-12-01
    oval:org.opensuse.security:def:49589
    P
    perl-CGI on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:51031
    P
    Security update for containerd, docker and go (Important)
    2020-12-01
    oval:org.opensuse.security:def:49532
    P
    libSDL2-2_0-0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50183
    P
    freerdp on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25224
    P
    Security update for libqt5-qtbase (Important)
    2020-12-01
    oval:org.opensuse.security:def:49524
    P
    gvfs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25649
    P
    Security update for libcdio (Low)
    2020-12-01
    oval:org.opensuse.security:def:49141
    P
    libXdmcp-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26468
    P
    Security update for go1.9 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49693
    P
    libsmi-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49288
    P
    pam_krb5 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50152
    P
    imobiledevice-tools on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50017
    P
    libvirglrenderer0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25033
    P
    Security update for openssl-1_0_0 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25022
    P
    Security update for spice (Important)
    2020-12-01
    oval:org.opensuse.security:def:25446
    P
    Security update for nfs-utils (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25795
    P
    Security update for kernel-source (Important)
    2020-12-01
    oval:org.opensuse.security:def:50087
    P
    openssh-fips on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49689
    P
    libpotrace0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50256
    P
    Security update for gpg2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:25305
    P
    Security update for java-1_8_0-ibm (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25751
    P
    Security update for libssh (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49368
    P
    zoo on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50969
    P
    Security update for perl-DBI (Important)
    2020-12-01
    oval:org.opensuse.security:def:49434
    P
    libexif-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25737
    P
    Security update for libpng12 (Moderate)
    2020-12-01
    oval:com.ubuntu.bionic:def:201871870000000
    V
    CVE-2018-7187 on Ubuntu 18.04 LTS (bionic) - low.
    2018-02-16
    oval:com.ubuntu.artful:def:20187187000
    V
    CVE-2018-7187 on Ubuntu 17.10 (artful) - low.
    2018-02-16
    oval:com.ubuntu.xenial:def:20187187000
    V
    CVE-2018-7187 on Ubuntu 16.04 LTS (xenial) - low.
    2018-02-16
    oval:com.ubuntu.xenial:def:201871870000000
    V
    CVE-2018-7187 on Ubuntu 16.04 LTS (xenial) - low.
    2018-02-16
    oval:com.ubuntu.bionic:def:20187187000
    V
    CVE-2018-7187 on Ubuntu 18.04 LTS (bionic) - low.
    2018-02-16
    oval:com.ubuntu.cosmic:def:20187187000
    V
    CVE-2018-7187 on Ubuntu 18.10 (cosmic) - low.
    2018-02-16
    oval:com.ubuntu.cosmic:def:201871870000000
    V
    CVE-2018-7187 on Ubuntu 18.10 (cosmic) - low.
    2018-02-16
    oval:com.ubuntu.trusty:def:20187187000
    V
    CVE-2018-7187 on Ubuntu 14.04 LTS (trusty) - low.
    2018-02-16
    BACK
    golang go *
    golang go *
    debian debian linux 7.0
    debian debian linux 9.0
    golang go 1.9.4