Golang: stdlib: security update to 1.8.4stdlib: security update to 1.9.1

critical Tenable Cloud Security Plugin ID 428544

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Go before 1.8.4 and 1.9.x before 1.9.1 allows "go get" remote command execution. Using custom domains, it
is possible to arrange things so that example.com/pkg1 points to a Subversion repository but
example.com/pkg1/pkg2 points to a Git repository. If the Subversion repository includes a Git checkout in
its pkg2 directory and some other work is done to ensure the proper ordering of operations, "go get" can
be tricked into reusing this Git checkout for the fetch of code from pkg2. If the Subversion repository's
Git checkout has malicious commands in .git/hooks/, they will execute on the system running "go get."
(CVE-2017-15041)

See Also

https://pkg.go.dev/vuln/GO-2022-0177

Plugin Details

Severity: Critical

ID: 428544

Version: Revision 1.2

Type: Local

Family: Golang

Published: 7/21/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.12

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2017-15041

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 8/9/2022

Vulnerability Publication Date: 10/4/2017

Reference Information

CVE: CVE-2017-15041

BID: 101196