Skip to content

tiagorlampert CHAOS vulnerable to arbitrary code execution

Moderate severity GitHub Reviewed Published May 7, 2024 to the GitHub Advisory Database • Updated May 9, 2024

Package

gomod github.com/tiagorlampert/CHAOS (Go)

Affected versions

< 0.0.0-20220716132853-b47438d36e3a

Patched versions

0.0.0-20220716132853-b47438d36e3a

Description

An issue in tiagorlampert CHAOS before 1b451cf62582295b7225caf5a7b506f0bad56f6b and 24c9e109b5be34df7b2bce8368eae669c481ed5e allows a remote attacker to execute arbitrary code via the unsafe concatenation of the filename argument into the buildStr string without any sanitization or filtering.

References

Published by the National Vulnerability Database May 7, 2024
Published to the GitHub Advisory Database May 7, 2024
Reviewed May 7, 2024
Last updated May 9, 2024

Severity

Moderate

Weaknesses

No CWEs

CVE ID

CVE-2024-33434

GHSA ID

GHSA-xfjj-f699-rc79

Source code

Checking history
See something to contribute? Suggest improvements for this vulnerability.