Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2024-24787

Description

On Darwin, building a Go module which contains CGO can trigger arbitrary code execution when using the Apple version of ld, due to usage of the -lto_library flag in a "#cgo LDFLAGS" directive.

POC

Reference

- https://groups.google.com/g/golang-announce/c/wkkO4P9stm0

Github

- https://github.com/CodingSimia/jenkins-shiftleft

- https://github.com/LOURC0D3/CVE-2024-24787-PoC

- https://github.com/adegoodyer/kubernetes-admin-toolkit

- https://github.com/drewtwitchell/scancompare

- https://github.com/fkie-cad/nvd-json-data-feeds

- https://github.com/nomi-sec/PoC-in-GitHub