Bug 1217834 (CVE-2023-45285) - VUL-0: CVE-2023-45285: go1.20,go1.21: cmd/go: go get may unexpectedly fallback to insecure git
Summary: VUL-0: CVE-2023-45285: go1.20,go1.21: cmd/go: go get may unexpectedly fallbac...
Status: RESOLVED FIXED
Alias: CVE-2023-45285
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/387174/
Whiteboard: CVSSv3.1:SUSE:CVE-2023-45285:6.5:(AV:...
Keywords:
Depends on:
Blocks:
 
Reported: 2023-12-06 02:16 UTC by Jeff Kowalczyk
Modified: 2024-05-24 10:31 UTC (History)
1 user (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Jeff Kowalczyk 2023-12-06 02:16:21 UTC
Using go get to fetch a module with the ".git" suffix may unexpectedly fallback to the insecure "git://" protocol if the module is unavailable via the secure "https://" and "git+ssh://" protocols, even if GOINSECURE is not set for said module. This only affects users who are not using the module proxy and are fetching modules directly (i.e. GOPROXY=off).

Thanks to David Leadbeater for reporting this issue.

This is CVE-2023-45285 and Go issue https://go.dev/issue/63845.
Comment 1 OBSbugzilla Bot 2023-12-06 08:25:07 UTC
This is an autogenerated message for OBS integration:
This bug (1217834) was mentioned in
https://build.opensuse.org/request/show/1131274 Factory / go1.20
https://build.opensuse.org/request/show/1131275 Factory / go1.21
Comment 3 Maintenance Automation 2023-12-11 20:36:21 UTC
SUSE-SU-2023:4709-1: An update that solves three vulnerabilities and has one security fix can now be installed.

Category: security (important)
Bug References: 1212475, 1216943, 1217833, 1217834
CVE References: CVE-2023-39326, CVE-2023-45284, CVE-2023-45285
Sources used:
openSUSE Leap 15.4 (src): go1.21-1.21.5-150000.1.18.1
openSUSE Leap 15.5 (src): go1.21-1.21.5-150000.1.18.1
Development Tools Module 15-SP4 (src): go1.21-1.21.5-150000.1.18.1
Development Tools Module 15-SP5 (src): go1.21-1.21.5-150000.1.18.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 4 Maintenance Automation 2023-12-11 20:36:24 UTC
SUSE-SU-2023:4708-1: An update that solves three vulnerabilities and has one security fix can now be installed.

Category: security (important)
Bug References: 1206346, 1216943, 1217833, 1217834
CVE References: CVE-2023-39326, CVE-2023-45284, CVE-2023-45285
Sources used:
openSUSE Leap 15.4 (src): go1.20-1.20.12-150000.1.35.1
openSUSE Leap 15.5 (src): go1.20-1.20.12-150000.1.35.1
Development Tools Module 15-SP4 (src): go1.20-1.20.12-150000.1.35.1
Development Tools Module 15-SP5 (src): go1.20-1.20.12-150000.1.35.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 6 Maintenance Automation 2023-12-20 16:30:06 UTC
SUSE-SU-2023:4931-1: An update that solves three vulnerabilities and has one security fix can now be installed.

Category: security (important)
Bug References: 1212475, 1216943, 1217833, 1217834
CVE References: CVE-2023-39326, CVE-2023-45284, CVE-2023-45285
Sources used:
Development Tools Module 15-SP5 (src): go1.21-openssl-1.21.5.1-150000.1.8.1
openSUSE Leap 15.4 (src): go1.21-openssl-1.21.5.1-150000.1.8.1
openSUSE Leap 15.5 (src): go1.21-openssl-1.21.5.1-150000.1.8.1
Development Tools Module 15-SP4 (src): go1.21-openssl-1.21.5.1-150000.1.8.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 7 Maintenance Automation 2023-12-20 16:30:09 UTC
SUSE-SU-2023:4930-1: An update that solves three vulnerabilities and has one security fix can now be installed.

Category: security (important)
Bug References: 1206346, 1216943, 1217833, 1217834
CVE References: CVE-2023-39326, CVE-2023-45284, CVE-2023-45285
Sources used:
openSUSE Leap 15.4 (src): go1.20-openssl-1.20.12.1-150000.1.17.1
openSUSE Leap 15.5 (src): go1.20-openssl-1.20.12.1-150000.1.17.1
Development Tools Module 15-SP4 (src): go1.20-openssl-1.20.12.1-150000.1.17.1
Development Tools Module 15-SP5 (src): go1.20-openssl-1.20.12.1-150000.1.17.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 11 Andrea Mattiazzo 2024-05-24 10:31:11 UTC
All done, closing.