cbcvebase.
CVE-2018-16873
published 2018-12-14

CVE-2018-16873: In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to remote code execution when executed with the -u flag and the import path of…

PriorityP266high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
66.25%
99.2th percentile
In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to remote code execution when executed with the -u flag and the import path of a malicious Go package, or a package that imports it directly or indirectly. Specifically, it is only vulnerable in GOPATH mode, but not in module mode (the distinction is documented at https://golang.org/cmd/go/#hdr-Module_aware_go_get). Using custom domains, it's possible to arrange things so that a Git repository is cloned to a folder named ".git" by using a vanity import path that ends with "/.git". If the Git repository root contains a "HEAD" file, a "config" file, an "objects" directory, a "refs" directory, with some work to ensure the proper ordering of operations, "go get -u" can be tricked into considering the parent directory as a repository root, and running Git commands on it. That will use the "config" file in the original Git repository root for its configuration, and if that config file contains malicious commands, they will execute on the system running "go get -u".

Affected

8 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
golanggo< 1.10.61.10.6
golanggo>= 1.11.0 < 1.11.31.11.3
opensusebackports_sle
opensuseleap
opensuseleap
opensuseleap
suselinux_enterprise_server

Detection & IOCsextracted from sources · hover to see the quote

path.git
filenameHEAD
filenameconfig
commandgo get -u
  • Flag exploitation: the vulnerability is only triggered when 'go get' is invoked with the -u flag; monitor or restrict use of 'go get -u' in CI/CD pipelines and build environments.
  • GOPATH mode only: exploitation requires GOPATH mode; environments running in module mode are not vulnerable. Verify build mode in affected pipelines.
  • Vanity import path ending with '/.git': detect or block import paths that terminate with '/.git' as these are used to clone a repo into a folder named '.git', enabling the parent-directory confusion.
  • Malicious Git config execution: the attack payload is delivered via a malicious 'config' file in the cloned Git repository root; inspect Git config files in GOPATH for unexpected hook or command entries.
  • ·Only Go versions before 1.10.6 and 1.11.x before 1.11.3 are vulnerable; upgrade to 1.10.6+ or 1.11.3+ to remediate.
  • ·Module mode is NOT affected; only GOPATH mode is exploitable. Detection and mitigation efforts should focus on GOPATH-mode build environments.

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.1HIGH
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.