MEDIUM4.7
GHSA-7g3v-4ggr-xvjf
Croc may expose secret to local users
Quick fix
GHSA-7g3v-4ggr-xvjf — github.com/schollz/croc/v9: upgrade to the fixed version with the command below.
go get github.com/schollz/croc/v9@v9.6.16Details
An issue was discovered in Croc before 9.6.16. The shared secret, located on a command line, can be read by local users who list all processes and their arguments.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/schollz/croc/v9
Introduced in:
0Fixed in: 9.6.16Fix
go get github.com/schollz/croc/v9@v9.6.16References
- https://nvd.nist.gov/vuln/detail/CVE-2023-43621[ADVISORY]
- https://github.com/schollz/croc/issues/598[WEB]
- https://github.com/schollz/croc/pull/701[WEB]
- https://github.com/schollz/croc/commit/863dabb93a271f41b3431c4384357e1856a69533[WEB]
- https://github.com/schollz/croc[PACKAGE]
- https://www.openwall.com/lists/oss-security/2023/09/08/2[WEB]
- http://www.openwall.com/lists/oss-security/2023/09/21/5[WEB]