7.5
CVSSv3

CVE-2020-28366

Published: 18/11/2020 Updated: 07/11/2023
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
CVSS v3 Base Score: 7.5 | Impact Score: 5.9 | Exploitability Score: 1.6
VMScore: 455
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

Go prior to 1.14.12 and 1.15.x prior to 1.15.4 allows Denial of Service. (CVE-2020-28362) Go prior to 1.14.12 and 1.15.x prior to 1.15.5 allows Code Injection. (CVE-2020-28366) Go prior to 1.14.12 and 1.15.x prior to 1.15.5 allows Argument Injection. (CVE-2020-28367)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

golang go

fedoraproject fedora 32

fedoraproject fedora 33

netapp trident -

netapp cloud insights telegraf agent -

Vendor Advisories

Synopsis Moderate: go-toolset-114-golang security update Type/Severity Security Advisory: Moderate Topic An update for go-toolset-114-golang is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scor ...
Synopsis Moderate: Red Hat OpenShift Serverless Client kn 1120 Type/Severity Security Advisory: Moderate Topic Red Hat OpenShift Serverless Client kn 1120Red Hat Product Security has rated this update as having a security impactof Moderate A Common Vulnerability Scoring System (CVSS) base score,which g ...
Synopsis Moderate: go-toolset:rhel8 security update Type/Severity Security Advisory: Moderate Topic An update for the go-toolset:rhel8 module is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring ...
Synopsis Moderate: Release of OpenShift Serverless 1120 Type/Severity Security Advisory: Moderate Topic Release of OpenShift Serverless 1120Red Hat Product Security has rated this update as having a security impactof Moderate A Common Vulnerability Scoring System (CVSS) base score,which gives a detaile ...
Go before 11412 and 115x before 1154 allows Denial of Service (CVE-2020-28362) Go before 11412 and 115x before 1155 allows Code Injection (CVE-2020-28366) Go before 11412 and 115x before 1155 allows Argument Injection (CVE-2020-28367) ...
Go before 11412 and 115x before 1154 allows Denial of Service (CVE-2020-28362) Go before 11412 and 115x before 1155 allows Code Injection (CVE-2020-28366) Go before 11412 and 115x before 1155 allows Argument Injection (CVE-2020-28367) ...
A flaw was found in go beforer 1155 where the go command may execute arbitrary code at build time when cgo is in use This may occur when running go get on a malicious package, or any other command that builds untrusted code ...