ZeroHour

CVE-2022-23773

CVSS 3.1
7.5 high
EPSS
3%p85
Published
()
Modified
Description

cmd/go in Go before 1.16.14 and 1.17.x before 1.17.7 can misinterpret branch names that falsely appear to be version tags. This can lead to incorrect access control if an actor is supposed to be able to create branches but not tags.

Vendors
golangnetapp
Products
go, beegfs csi driver, cloud insights telegraf agent, kubernetes monitoring operator, storagegrid
Weakness
CWE-436
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.