CVE-2022-29583

service_windows.go in the kardianos service package for Go omits quoting that is sometimes needed for execution of a Windows service executable from the intended directory.
References
Link Resource
https://github.com/kardianos/service/pull/290 Patch Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:service_project:service:-:*:*:*:*:go:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

Information

Published : 2022-04-22 16:15

Updated : 2022-05-03 19:44


NVD link : CVE-2022-29583

Mitre link : CVE-2022-29583


JSON object : View

Products Affected

microsoft

  • windows

service_project

  • service
CWE
CWE-426

Untrusted Search Path