High severity7.5NVD Advisory· Published Jan 26, 2021· Updated Jun 17, 2026
CVE-2021-3115
CVE-2021-3115
Description
Go before 1.14.14 and 1.15.x before 1.15.7 on Windows is vulnerable to Command Injection and remote code execution when using the "go get" command to fetch modules that make use of cgo (for example, cgo can execute a gcc program from an untrusted download).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
31- Go/Godescription
- osv-coords26 versionspkg:rpm/suse/go1.14&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSSpkg:rpm/suse/go1.14&distro=SUSE%20Manager%20Proxy%204.0pkg:rpm/suse/go1.14&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP2pkg:rpm/suse/go1.14&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-BCLpkg:rpm/suse/go1.14&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1pkg:rpm/suse/go1.14&distro=SUSE%20Manager%20Server%204.0pkg:rpm/suse/go1.14&distro=SUSE%20Enterprise%20Storage%206pkg:rpm/suse/go1.15&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP2pkg:rpm/suse/go1.15&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/go1.15&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-BCLpkg:rpm/suse/go1.15&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSSpkg:rpm/suse/go1.15&distro=SUSE%20Manager%20Proxy%204.0pkg:rpm/suse/go1.15&distro=SUSE%20Manager%20Retail%20Branch%20Server%204.0pkg:rpm/suse/go1.15&distro=SUSE%20Manager%20Server%204.0pkg:rpm/suse/go1.15&distro=SUSE%20Enterprise%20Storage%206pkg:rpm/suse/go1.15&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1pkg:rpm/opensuse/go1.15&distro=openSUSE%20Tumbleweedpkg:rpm/suse/go1.14&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:bitnami/golangpkg:rpm/suse/go1.14&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/go1.15&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/go1.14&distro=SUSE%20Manager%20Retail%20Branch%20Server%204.0pkg:rpm/opensuse/go1.15&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/go1.14&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/go1.14&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/go1.14&distro=openSUSE%20Tumbleweed
< 1.14.14-1.32.1+ 25 more
- (no CPE)range: < 1.14.14-1.32.1
- (no CPE)range: < 1.14.14-1.32.1
- (no CPE)range: < 1.14.14-1.32.1
- (no CPE)range: < 1.14.14-1.32.1
- (no CPE)range: < 1.14.14-1.32.1
- (no CPE)range: < 1.14.14-1.32.1
- (no CPE)range: < 1.14.14-1.32.1
- (no CPE)range: < 1.15.7-1.17.1
- (no CPE)range: < 1.15.7-1.17.1
- (no CPE)range: < 1.15.7-1.17.1
- (no CPE)range: < 1.15.7-1.17.1
- (no CPE)range: < 1.15.7-1.17.1
- (no CPE)range: < 1.15.7-1.17.1
- (no CPE)range: < 1.15.7-1.17.1
- (no CPE)range: < 1.15.7-1.17.1
- (no CPE)range: < 1.15.7-1.17.1
- (no CPE)range: < 1.15.15-1.2
- (no CPE)range: < 1.14.14-1.32.1
- (no CPE)range: < 1.14.14
- (no CPE)range: < 1.14.14-1.32.1
- (no CPE)range: < 1.15.7-1.17.1
- (no CPE)range: < 1.14.14-1.32.1
- (no CPE)range: < 1.15.7-lp152.8.1
- (no CPE)range: < 1.14.14-lp152.2.18.1
- (no CPE)range: < 1.14.14-lp151.28.1
- (no CPE)range: < 1.14.15-1.6
- cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:cloud_insights_telegraf_agent:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:storagegrid:-:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
5- blog.golang.org/path-securitynvdVendor Advisory
- groups.google.com/g/golang-announce/c/mperVMGa98wnvdRelease NotesThird Party Advisory
- security.gentoo.org/glsa/202208-02nvdThird Party Advisory
- security.netapp.com/advisory/ntap-20210219-0001/nvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YWAYJGXWC232SG3UR3TR574E6BP3OSQQ/nvd
News mentions
0No linked articles in our index yet.