CVE-2024-45339: Vulnerability when creating log files in github.com/golang/glog

Published Jan 28, 2025
·
Updated

Vulnerability when creating log files in github.com/golang/glog

Other sources

When logs are written to a widely-writable directory (the default), an unprivileged attacker may predict a privileged process's log file path and pre-create a symbolic link to a sensitive file in its place. When that privileged process runs, it will follow the planted symlink and overwrite that sensitive file. To fix that, glog now causes the program to exit (with status code 2) when it finds that the configured log file already exists.

MITRE

Affected Software

11 affected componentsFixes available
Google glog
go/github.com/golang/glog<1.2.4
1.2.4
IBM Edge Application Manager<=4.5
Microsoft azl3 vitess 19.0.4-4
Microsoft azl3 sriov-network-device-plugin 3.7.0-3
Microsoft cbl2 sriov-network-device-plugin 3.6.2-8
Microsoft cbl2 vitess 17.0.7-4
Microsoft cbl2 vitess 17.0.7-8
Microsoft azl3 sriov-network-device-plugin 3.7.0-4
Microsoft cbl2 sriov-network-device-plugin 3.6.2-9
Microsoft azl3 vitess 19.0.4-7

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade go/github.com/golang/glog to a version that resolves this vulnerability.

    Fixed in 1.2.4
  2. Configuration

    Update to the glog behavior where, if the configured log file already exists, glog exits with status code 2 to prevent symlink/hardlink log file pre-creation attacks.

    github.com/golang/glog log file creation behavior = exit with status code 2 when configured log file already exists

Event History

Jan 28, 2025
CVE Published
via MITRE·01:03 AM
Data Sourced
via MITRE·01:03 AM
DescriptionWeakness
Data Sourced
via Red Hat·02:01 AM
DescriptionSeverityAffected Software
Data Sourced
via NVD·02:15 AM
DescriptionSeverity
Advisory Published
via GitHub·05:29 PM
Feb 11, 2025
Data Sourced
via Microsoft·08:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:00 AM
Affected Software
Updated
via Microsoft·08:00 AM
Affected Software
Updated
via Microsoft·08:00 AM
DescriptionSeverity
Aug 20, 2025
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-45339?

CVE-2024-45339 has been classified as a high severity vulnerability due to the potential for privilege escalation.

2

How do I fix CVE-2024-45339?

To fix CVE-2024-45339, ensure that logs are written to a secure directory that is not widely writable by unprivileged users.

3

What are the potential impacts of CVE-2024-45339?

The potential impacts of CVE-2024-45339 include unauthorized access to sensitive files and potential complete system compromise.

4

Which software versions are affected by CVE-2024-45339?

CVE-2024-45339 affects versions prior to 1.2.4 of the Go package github.com/golang/glog.

5

Who is the vendor associated with CVE-2024-45339?

The vendor associated with CVE-2024-45339 is Google, which maintains the glog package.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203