Fedora Account System
Red Hat Associate
Red Hat Customer
Previously, a user operating inside of a malicious Go project that defines a bogus golang.org/fips140 and operates a malicious GOMODPROXY the user chooses to connect to can serve an arbitrary module in its place. We now unpack the trusted ziphash for the bundled golang.org/fips140 module and construct its entry in the GOMODCACHE such that it can be verified by the toolchain.
CVSS Justification =================== AV:L -- Exploitation requires running the local go command on the victim host. AC:H -- Attacker must supply a malicious Go project and the user must also use an untrusted module proxy. PR:L -- A local account (developer/build user) is required to invoke the go toolchain; an unauthenticated remote party cannot trigger the flaw on its own. UI:R -- The user must open/operate inside the malicious project (and choose that proxy). S:U -- Impact stays in the same security authority as the user running go. C:H -- Successful exploitation can execute attacker-controlled code in that user context. I:H -- Attacker-controlled modules/toolchain can alter build integrity. A:H -- Arbitrary code execution can disrupt or terminate the build/user environment.