GHSA-x5c7-x7m2-rhmf
Local directory executable lookup in sops (Windows-only)
Quick fix
GHSA-x5c7-x7m2-rhmf — go.mozilla.org/sops/v3: upgrade to the fixed version with the command below.
go get go.mozilla.org/sops/v3@v3.7.1Details
### Impact Windows users using the sops direct editor option (`sops file.yaml`) can have a local executable named either `vi`, `vim`, or `nano` executed if running sops from `cmd.exe`
This attack is only viable if an attacker is able to place a malicious binary within the directory you are running sops from. As well, this attack will only work when using `cmd.exe` or the Windows C library [SearchPath function](https://docs.microsoft.com/en-us/windows/win32/api/processenv/nf-processenv-searchpatha). This is a result of these Windows tools including `.` within their `PATH` by default.
**If you are using sops within untrusted directories on Windows via `cmd.exe`, please upgrade immediately**
**As well, if you have `.` within your default $PATH, please upgrade immediately.**
More information can be found on the official Go blog: https://blog.golang.org/path-security
### Patches The problem has been resolved in v3.7.1
Now, if Windows users using cmd.exe run into this issue, a warning message will be printed: `vim resolves to executable in current directory (.\vim.exe)`
### References * https://blog.golang.org/path-security
### For more information If you have any questions or comments about this advisory: * Open a discussion in [sops](https://github.com/mozilla/sops/discussions)
Are you affected?
Enter the version of the package you're using.