Input validation error in Go programming language - CVE-2023-45283

 

Input validation error in Go programming language - CVE-2023-45283

Published: November 17, 2023


Vulnerability identifier: #VU83255
CSH Severity: Low
CVSS v4 BT: 1.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2023-45283
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to bypass implemented security restrictions.

The vulnerability exists due to the path/filepath package does not recognize paths with a "??" prefix as Root Local Device path prefix. A local user can abuse such behavior and bypass implemented security restrictions.

Affected software

Go programming language
Gentoo Linux
Amazon Linux AMI
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Development Tools Module
openSUSE Leap
Anolis OS
AdGuard Home
Event Streams
IBM Concert Software
Consul Enterprise
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Robotic Process Automation
IBM Observability with Instana
Splunk Enterprise
Db2 Rest
DB2 on Cloud Pak for Data
Storage Protect Server
Storage Protect Plus Container Agent
Storage Protect Plus Server
Robotic Process Automation for Cloud Pak
go1.20-openssl-debuginfo
go1.20-openssl-doc
go1.20-openssl-race
go1.20-openssl
go1.20-debuginfo
go1.20
go1.20-doc
go1.20-race
golang-docs
golang-shared
golang-bin
golang-misc
golang-src
golang
golang-tests
go1.21-openssl-doc
go1.21-openssl-race
go1.21-openssl
go1.21
go1.21-race
go1.21-doc
dev-lang/go
IBM CICS TX Standard

How to mitigate CVE-2023-45283

Install updates from vendor's website.

Go programming language - addressed in versions 1.20.11, 1.21.4
AdGuard Home - addressed in versions 0.107.42, 0.108.0-b.51
IBM Concert Software - update to 1.0.5
Consul Enterprise - addressed in versions 1.15.8, 1.16.4, 1.17.1
Splunk Enterprise - addressed in versions 9.1.6, 9.2.3, 9.3.1
Event Streams - update to 11.3.2
Db2 Rest - update to 1.0.0.301
go1.20-openssl-debuginfo - update to 1.20.11.1-150000.1.14.1
go1.20-openssl-doc - update to 1.20.11.1-150000.1.14.1
go1.20-openssl-race - update to 1.20.11.1-150000.1.14.1
go1.20-openssl - update to 1.20.11.1-150000.1.14.1
go1.20-debuginfo - update to 1.20.11-150000.1.32.1
go1.20 - update to 1.20.11-150000.1.32.1
go1.20-doc - update to 1.20.11-150000.1.32.1
go1.20-race - update to 1.20.11-150000.1.32.1
golang-docs - update to 1.20.12-1
golang-shared - update to 1.20.12-1
golang-bin - update to 1.20.12-1
golang-misc - update to 1.20.12-1
golang-src - update to 1.20.12-1
golang - update to 1.20.12-1
golang-tests - update to 1.20.12-1
golang - update to 1.20.12-1.49
go1.21-openssl-doc - update to 1.21.4.1-150000.1.5.1
go1.21-openssl-race - update to 1.21.4.1-150000.1.5.1
go1.21-openssl - update to 1.21.4.1-150000.1.5.1
go1.21 - update to 1.21.4-150000.1.15.1
go1.21-race - update to 1.21.4-150000.1.15.1
go1.21-doc - update to 1.21.4-150000.1.15.1
dev-lang/go - update to 1.22.3
DB2 on Cloud Pak for Data - update to 4.8.4
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.8.5
Storage Protect Server - update to 8.1.23
Storage Protect Plus Container Agent - update to 10.1.12.7
Storage Protect Plus Server - update to 10.1.16.2
IBM CICS TX Standard - update to 11.1.0.0 ifix18
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.15, 23.0.15
IBM Robotic Process Automation - addressed in versions 21.0.7.15, 23.0.15
IBM Observability with Instana - update to 281

External References

Related Security Bulletins