—
GO-2024-3133
Chaosblade vulnerable to OS command execution in github.com/chaosblade-io/chaosblade
Quick fix
GO-2024-3133 — github.com/chaosblade-io/chaosblade: upgrade to the fixed version with the command below.
go get github.com/chaosblade-io/chaosblade@v1.7.4Details
Chaosblade vulnerable to OS command execution in github.com/chaosblade-io/chaosblade
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/chaosblade-io/chaosblade
Introduced in:
0.0.3Fixed in: 1.7.4Fix
go get github.com/chaosblade-io/chaosblade@v1.7.4References
- https://github.com/advisories/GHSA-723h-x37g-f8qm[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2023-47105[ADVISORY]
- https://github.com/chaosblade-io/chaosblade/commit/6bc73c31e14ea2b1bfc30f359e1fe952859d9adc[FIX]
- https://github.com/chaosblade-io/chaosblade/blob/0a07380c9899febb2b544132783b376b44226cca/exec/os/executor.go#L68[WEB]
- https://narrow-oatmeal-0c0.notion.site/ChaosBlade-Remote-Command-Execution-CVE-2023-47105-4f5459046488436caaec2bced6ff26d7[WEB]