VDB
Sign up
LOW

GHSA-x5c7-x7m2-rhmf

Local directory executable lookup in sops (Windows-only)

Quick fix

GHSA-x5c7-x7m2-rhmf — go.mozilla.org/sops/v3: upgrade to the fixed version with the command below.

go get go.mozilla.org/sops/v3@v3.7.1

Details

### Impact Windows users using the sops direct editor option (`sops file.yaml`) can have a local executable named either `vi`, `vim`, or `nano` executed if running sops from `cmd.exe`

This attack is only viable if an attacker is able to place a malicious binary within the directory you are running sops from. As well, this attack will only work when using `cmd.exe` or the Windows C library [SearchPath function](https://docs.microsoft.com/en-us/windows/win32/api/processenv/nf-processenv-searchpatha). This is a result of these Windows tools including `.` within their `PATH` by default.

**If you are using sops within untrusted directories on Windows via `cmd.exe`, please upgrade immediately**

**As well, if you have `.` within your default $PATH, please upgrade immediately.**

More information can be found on the official Go blog: https://blog.golang.org/path-security

### Patches The problem has been resolved in v3.7.1

Now, if Windows users using cmd.exe run into this issue, a warning message will be printed: `vim resolves to executable in current directory (.\vim.exe)`

### References * https://blog.golang.org/path-security

### For more information If you have any questions or comments about this advisory: * Open a discussion in [sops](https://github.com/mozilla/sops/discussions)

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/go.mozilla.org/sops/v3
Introduced in: 0Fixed in: 3.7.1
Fixgo get go.mozilla.org/sops/v3@v3.7.1

References