VDB
Sign up
CRITICAL9.6

GHSA-vfrj-fv6p-3cpf

Brook's tproxy server is vulnerable to a drive-by command injection.

Quick fix

GHSA-vfrj-fv6p-3cpf — github.com/txthinking/brook: upgrade to the fixed version with the command below.

go get github.com/txthinking/brook@v20230606

Details

The `tproxy` server is vulnerable to a drive-by command injection. An attacker may fool a victim into visiting a malicious web page which will trigger requests to the local `tproxy` service leading to remote code execution.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/txthinking/brook
Introduced in: 0Fixed in: 20230606
Fixgo get github.com/txthinking/brook@v20230606

References