CVE-2020-28367
Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time
Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time via malicious gcc flags specified via a #cgo directive.
HIGH · CVSS 7.5
EPSS 0.00272
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0