CVE-2018-6574

Go before 1.8.7, Go 1.9.x before 1.9.4, and Go 1.10 pre-releases before Go 1.10rc2 allow "go get" remote command execution during source code build, by leveraging the gcc or clang plugin feature, because -fplugin= and -plugin= arguments were not blocked.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 97%
Affected Products (NVD)
VendorProductVersion
golanggo
𝑥
≤ 1.8.6
golanggo
1.9
golanggo
1.9.1
golanggo
1.9.2
golanggo
1.9.3
golanggo
1.10:beta1
golanggo
1.10:beta2
golanggo
1.10:rc1
debiandebian_linux
9.0
redhatenterprise_linux_server
7.0
redhatenterprise_linux_server_aus
7.6
redhatenterprise_linux_server_eus
7.6
redhatenterprise_linux_server_tus
7.6
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
golang
artful
dne
bionic
dne
cosmic
dne
disco
dne
eoan
dne
focal
dne
groovy
dne
hirsute
dne
impish
dne
jammy
dne
kinetic
dne
lunar
dne
mantic
dne
noble
dne
trusty
dne
xenial
dne
golang-1.6
artful
dne
bionic
dne
cosmic
dne
disco
dne
eoan
dne
focal
dne
groovy
dne
hirsute
dne
impish
dne
jammy
dne
kinetic
dne
lunar
dne
mantic
dne
noble
dne
trusty
dne
xenial
needs-triage
golang-1.7
artful
ignored
bionic
dne
cosmic
ignored
disco
dne
eoan
dne
focal
dne
groovy
dne
hirsute
dne
impish
dne
jammy
dne
kinetic
dne
lunar
dne
mantic
dne
noble
dne
trusty
dne
xenial
dne
golang-1.8
artful
ignored
bionic
needed
cosmic
ignored
disco
dne
eoan
dne
focal
dne
groovy
dne
hirsute
dne
impish
dne
jammy
dne
kinetic
dne
lunar
dne
mantic
dne
noble
dne
trusty
dne
xenial
dne
golang-1.9
artful
ignored
bionic
not-affected
cosmic
not-affected
disco
dne
eoan
dne
focal
dne
groovy
dne
hirsute
dne
impish
dne
jammy
dne
kinetic
dne
lunar
dne
mantic
dne
noble
dne
trusty
dne
xenial
dne
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
go
suse enterprise desktop 15 SP7
1.24-150000.3.43.1
fixed
suse enterprise sap 15 SP7
1.24-150000.3.43.1
fixed
suse enterprise server 15 SP7
1.24-150000.3.43.1
fixed
go-doc
suse enterprise desktop 15 SP7
1.24-150000.3.43.1
fixed
suse enterprise sap 15 SP7
1.24-150000.3.43.1
fixed
suse enterprise server 15 SP7
1.24-150000.3.43.1
fixed
go-race
suse enterprise desktop 15 SP7
1.24-150000.3.43.1
fixed
suse enterprise sap 15 SP7
1.24-150000.3.43.1
fixed
suse enterprise server 15 SP7
1.24-150000.3.43.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
golang
RHEL 7
0:1.9.4-1.el7
fixed
golang-bin
RHEL 7
0:1.9.4-1.el7
fixed
golang-docs
RHEL 7
0:1.9.4-1.el7
fixed
golang-misc
RHEL 7
0:1.9.4-1.el7
fixed
golang-src
RHEL 7
0:1.9.4-1.el7
fixed
golang-tests
RHEL 7
0:1.9.4-1.el7
fixed