5.1
CVSSv2

CVE-2021-3115

Published: 26/01/2021 Updated: 07/11/2023
CVSS v2 Base Score: 5.1 | Impact Score: 6.4 | Exploitability Score: 4.9
CVSS v3 Base Score: 7.5 | Impact Score: 5.9 | Exploitability Score: 1.6
VMScore: 454
Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

Go prior to 1.14.14 and 1.15.x prior to 1.15.7 on Windows is vulnerable to Command Injection and remote code execution when using the "go get" command to fetch modules that make use of cgo (for example, cgo can execute a gcc program from an untrusted download).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

golang go

fedoraproject fedora 33

netapp storagegrid -

netapp cloud insights telegraf agent -

Vendor Advisories

In Go before 11414 and 115x before 1157, crypto/elliptic/p224go can generate incorrect outputs, related to an underflow of the lowest limb during the final complete reduction in the P-224 field (CVE-2021-3114) Go before 11414 and 115x before 1157 on Windows is vulnerable to Command Injection and remote code execution when using the "g ...
A security issue was found in Go and fixed in versions 1157 and 11414 The go command may execute arbitrary code at build time when using cgo on Windows This can be triggered by running go get for a malicious package, or any other time the code is built This can be triggered by malicious packages which contain specifically named binaries whic ...