{"schema_version":"1.9.0","id":"GHSA-5qww-56gc-f66c","published":"2024-12-20T18:31:30Z","modified":"2025-01-07T16:27:06.142502Z","aliases":["CVE-2024-28892","GO-2024-3359"],"summary":"GoCast OS Command Injection vulnerability","details":"An OS command injection vulnerability exists in the name parameter of GoCast 1.1.3. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.","affected":[{"package":{"name":"github.com/mayuresh82/gocast","ecosystem":"Go","purl":"pkg:golang/github.com/mayuresh82/gocast"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"1.1.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/12/GHSA-5qww-56gc-f66c/GHSA-5qww-56gc-f66c.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-28892"},{"type":"PACKAGE","url":"https://github.com/mayuresh82/gocast"},{"type":"WEB","url":"https://talosintelligence.com/vulnerability_reports/TALOS-2024-1960"},{"type":"WEB","url":"https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1960"}],"database_specific":{"cwe_ids":["CWE-78"],"github_reviewed":true,"github_reviewed_at":"2024-12-26T16:02:05Z","nvd_published_at":"2024-11-21T15:15:29Z","severity":"CRITICAL"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}