Skip to content

os/exec:Does Golang involve CVE-2024-3566? #74281

Closed as not planned
Closed as not planned
@maxucheng0

Description

@maxucheng0

Go version

NA

Output of go env in your module/workspace:

NA

What did you do?

I noticed that there is an update on the NVD website regarding the vulnerability CVE-2024-3566(https://nvd.nist.gov/vuln/detail/CVE-2024-3566), which lists Go as one of the affected languages. However, upon reviewing the source material (https://kb.cert.org/vuls/id/123335), the conclusion is that it is not affected. Could you let me know if we have already conducted an analysis of this vulnerability? Thank you.

What did you see happen?

NA

What did you expect to see?

NA

Metadata

Metadata

Assignees

No one assigned

    Labels

    QuestionIssues that are questions about using Go.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions