CRITICAL9.6
GHSA-vfrj-fv6p-3cpf
Brook's tproxy server is vulnerable to a drive-by command injection.
Quick fix
GHSA-vfrj-fv6p-3cpf — github.com/txthinking/brook: upgrade to the fixed version with the command below.
go get github.com/txthinking/brook@v20230606Details
The `tproxy` server is vulnerable to a drive-by command injection. An attacker may fool a victim into visiting a malicious web page which will trigger requests to the local `tproxy` service leading to remote code execution.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/txthinking/brook
Introduced in:
0Fixed in: 20230606Fix
go get github.com/txthinking/brook@v20230606