VDB
Sign up
HIGH8.8

GHSA-p3j6-f45h-hw5f

tiagorlampert CHAOS vulnerable to command injections

Quick fix

GHSA-p3j6-f45h-hw5f — github.com/tiagorlampert/CHAOS: upgrade to the fixed version with the command below.

go get github.com/tiagorlampert/CHAOS@v0.0.0-20220716132853-b47438d36e3a

Details

An issue in tiagorlampert CHAOS v5.0.1 allows a remote attacker to execute arbitrary code via the BuildClient function within client_service.go

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/tiagorlampert/CHAOS
Introduced in: 0Fixed in: 0.0.0-20220716132853-b47438d36e3a
Fixgo get github.com/tiagorlampert/CHAOS@v0.0.0-20220716132853-b47438d36e3a

References