CVE-2017-15041

critical
Published 2017-10-05 · Modified 2024-05-20
CVSS v3
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
7.5
VIR risk
9.8

Description

Remote command execution via "go get" in cmd/go

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://groups.google.com/d/msg/golang-dev/RinSE3EiJBI/kYL7zb07AgAJ

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://golang.org/cl/68190

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://golang.org/cl/68022

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://github.com/golang/go/issues/22125

vendor Authored 2026-05-27

Vendor advisory: arch — https://security.archlinux.org/ASA-201710-15

OS impact

OSVersionStatusFixed in
arch archfixed2:1.9.1-1
debian debian9.0affected
redhat rhel7.6affected
redhat rhel7.7affected
redhat rhel7.0affected

Package impact

EcosystemPackageVulnerableFixed
golang Gotoolchain>=1.9.0-0,<1.9.11.8.4

Application impact

VendorProductVersionsFixed
golanggo{"endIncluding":"1.8.3"}
golanggo1.9
redhatdeveloper_tools1.0

References

Verify integrity in audit chain (admin only). AS-IS.