CVE-2023-45285
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Dec 6, 2023
Updated: Jan 20, 2024
Summary
CVE-2023-45285 is a vulnerability affecting the Go programming language's "go get" tool. When attempting to fetch a module with a ".git" suffix, the tool may unexpectedly revert to the insecure "git://" protocol if the module is not available via the secure "https://" and "git+ssh://" protocols. This issue only impacts users who have not enabled a module proxy and are directly fetching modules (GOPROXY=off).
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Golang Go
Advisories, Assessments, and Mitigations
Prioritize, Pinpoint, and Act to Prevent Vulnerability Exploits with Recorded Future
Note: This is just a basic overview providing quick insights into CVE-2023-45285 information. Gain full access to comprehensive CVE data, third party vulnerabilities, compromised credentials and more with Recorded Future
- Gain complete coverage of your cyber, third party, and physical attack surface
- Proactively mitigate threats before they turn into costly attacks
- Make fast, effective, data-driven decisions