Skip to content

x/vulndb: potential Go vuln in cmd/go: CVE-2024-45340 #3383

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
tatianab opened this issue Jan 13, 2025 · 1 comment
Closed

x/vulndb: potential Go vuln in cmd/go: CVE-2024-45340 #3383

tatianab opened this issue Jan 13, 2025 · 1 comment

Comments

@tatianab
Copy link
Contributor

tatianab commented Jan 13, 2025

cmd/go: GOAUTH credential leak

Credentials provided via the new GOAUTH feature were not being properly
segmented by domain, allowing a malicious server to request credentials they
should not have access to. By default, unless otherwise set, this only affected
credentials stored in the users .netrc file.

Thanks to Juho Forsén of Mattermost for reporting this issue.

This is CVE-2024-45340 and Go issue https://go.dev/issue/71249.

@tatianab tatianab assigned neild and unassigned neild Jan 17, 2025
@tatianab tatianab changed the title x/vulndb: potential Go vuln in <placeholder>: CVE-2024-45340 x/vulndb: potential Go vuln in cmd/go: CVE-2024-45340 Jan 27, 2025
@gopherbot
Copy link
Contributor

Change https://go.dev/cl/644855 mentions this issue: data/reports: add 5 reports

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants