Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2022-30580

Description

Code injection in Cmd.Start in os/exec before Go 1.17.11 and Go 1.18.3 allows execution of any binaries in the working directory named either "..com" or "..exe" by calling Cmd.Run, Cmd.Start, Cmd.Output, or Cmd.CombinedOutput when Cmd.Path is unset.

POC

Reference

- https://groups.google.com/g/golang-announce/c/TzIC9-t8Ytg/m/IWz5T6x7AAAJ

Github

- https://github.com/8-cm/kube-dump

- https://github.com/ARPSyndicate/cvemon

- https://github.com/JakubWierzchowski/manier

- https://github.com/agadecki/malware-cryptominer-container

- https://github.com/drewtwitchell/scancompare

- https://github.com/henriquebesing/container-security

- https://github.com/kb5fls/container-security

- https://github.com/runwhen-contrib/helm-charts

- https://github.com/ruzickap/malware-cryptominer-container