Fedora Account System
Red Hat Associate
Red Hat Customer
Previously, a user operating inside of a malicious Go project that defines a bogus golang.org/toolchain go.sum entry and operates a malicious GOMODPROXY the user chooses to use can bypass the intended checksum. We now ensure that golang.org/toolchain always goes to the network for the canonical checksum.
CVSS Justification =================== AV:L -- Exploitation requires running the local go command on the victim host. AC:H -- Attacker must supply a malicious Go project and the user must also use an untrusted module proxy. PR:L -- A local account (developer/build user) is required to invoke the go toolchain; an unauthenticated remote party cannot trigger the flaw on its own. UI:R -- The user must open/operate inside the malicious project (and choose that proxy). S:U -- Impact stays in the same security authority as the user running go. C:H -- Successful exploitation can execute attacker-controlled code in that user context. I:H -- Attacker-controlled modules/toolchain can alter build integrity. A:H -- Arbitrary code execution can disrupt or terminate the build/user environment.