Disputed: OS Command injection in github.com/kardianos/service
High severity
GitHub Reviewed
Published
Apr 23, 2022
to the GitHub Advisory Database
•
Updated May 24, 2023
Withdrawn
This advisory was withdrawn on May 24, 2023
Description
Published by the National Vulnerability Database
Apr 22, 2022
Published to the GitHub Advisory Database
Apr 23, 2022
Reviewed
Apr 26, 2022
Withdrawn
May 24, 2023
Last updated
May 24, 2023
service_windows.go in the kardianos service package for Go omits quoting that is sometimes needed for execution of a Windows service executable from the intended directory.
The validity of this vulnerability has been questioned and the reporter has requested that the CVE be disputed.
References