CVE-2020-28366
Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time
Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time via a malicious unquoted symbol name in a linked object file.
HIGH · CVSS 7.5
EPSS 0.00167
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0