{"id":"GHSA-p3j6-f45h-hw5f","summary":"tiagorlampert CHAOS vulnerable to command injections","details":"An issue in tiagorlampert CHAOS v5.0.1 allows a remote attacker to execute arbitrary code via the BuildClient function within client_service.go","aliases":["CVE-2024-30850","CVE-2024-33434","GHSA-xfjj-f699-rc79","GO-2024-2822"],"modified":"2024-05-09T18:36:35Z","published":"2024-04-12T06:33:24Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-04-12T21:23:30Z","nvd_published_at":"2024-04-12T06:15:06Z","cwe_ids":["CWE-78"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-30850"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-33434"},{"type":"WEB","url":"https://github.com/tiagorlampert/CHAOS/pull/95"},{"type":"WEB","url":"https://github.com/tiagorlampert/CHAOS/commit/1b451cf62582295b7225caf5a7b506f0bad56f6b"},{"type":"WEB","url":"https://github.com/tiagorlampert/CHAOS/commit/24c9e109b5be34df7b2bce8368eae669c481ed5e"},{"type":"WEB","url":"https://blog.chebuya.com/posts/remote-code-execution-on-chaos-rat-via-spoofed-agents"},{"type":"WEB","url":"https://gist.github.com/slimwang/d1ec6645ba9012a551ea436679244496"},{"type":"PACKAGE","url":"https://github.com/tiagorlampert/CHAOS"}],"affected":[{"package":{"name":"github.com/tiagorlampert/CHAOS","ecosystem":"Go","purl":"pkg:golang/github.com/tiagorlampert/CHAOS"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.0.0-20220716132853-b47438d36e3a"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/04/GHSA-p3j6-f45h-hw5f/GHSA-p3j6-f45h-hw5f.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}