Go Vuln the Golang 漏洞数据库


什么是govuln?

Govuln 是一个新的漏洞数据库,用于查找代码中易受攻击的软件包并防止供应链攻击

如何安装 thecligovulncheck

govulncheck是用于与数据库交互并对照数据库检查代码的命令行推理,请使用以下命令安装它:

go install golang.org/x/vuln/cmd/govulncheck@latest

然后在项目中运行它,如下所示:

govulncheck .

它将在您的依赖项中搜索易受攻击的包。下面是输出的示例:

govulncheck is an experimental tool. Share feedback at https://go.dev/s/govulncheck-feedback.

Scanning for dependencies with known vulnerabilities...
No vulnerabilities found.

=== Informational ===

The vulnerabilities below are in packages that you import, but your code
doesn't appear to call any vulnerable functions. You may not need to take any
action. See https://pkg.go.dev/golang.org/x/vuln/cmd/govulncheck
for details.

Vulnerability #1: GO-2022-1095
  Due to unsanitized NUL values, attackers may be able to maliciously set environment variables on Windows.

  In syscall.StartProcess and os/exec.Cmd, invalid environment variable values containing NUL values are not properly checked for. A malicious environment variable value can exploit this behavior to set a value for a different environment variable. For example, the environment variable string "A=B/x00C=D" sets the variables "A=B" and "C=D".
  Found in: syscall@go1.19.1
  Fixed in: syscall@go1.19.3
  More info: https://pkg.go.dev/vuln/GO-2022-1095

有关更多详细信息

原创文章,作者:ItWorker,如若转载,请注明出处:https://blog.ytso.com/292901.html

(0)
上一篇 2022年11月10日
下一篇 2022年11月10日

相关推荐

发表回复

登录后才能评论