Vulnerability Report: GO-2024-2863
- CVE-2024-35183, GHSA-8fg7-hp93-qhvr
- Affects: github.com/wolfi-dev/wolfictl
- Published: Jun 04, 2024
- Unreviewed
wolfictl leaks GitHub tokens to remote non-GitHub git servers in github.com/wolfi-dev/wolfictl
For detailed information about this vulnerability, visit https://github.com/wolfi-dev/wolfictl/security/advisories/GHSA-8fg7-hp93-qhvr or https://nvd.nist.gov/vuln/detail/CVE-2024-35183.
Affected Modules
-
PathGo Versions
-
before v0.16.10
Aliases
References
- https://github.com/wolfi-dev/wolfictl/security/advisories/GHSA-8fg7-hp93-qhvr
- https://nvd.nist.gov/vuln/detail/CVE-2024-35183
- https://github.com/wolfi-dev/wolfictl/commit/0d06e1578300327c212dda26a5ab31d09352b9d0
- https://github.com/wolfi-dev/wolfictl/commit/403e93569f46766b4e26e06cf9cd0cae5ee0c2a2
- https://github.com/wolfi-dev/wolfictl/blob/488b53823350caa706de3f01ec0eded9350c7da7/pkg/update/update.go#L143
- https://github.com/wolfi-dev/wolfictl/blob/4dd6c95abb4bc0f9306350a8601057bd7a92bded/pkg/update/deps/cleanup.go#L49
- https://github.com/wolfi-dev/wolfictl/blob/6d99909f7b1aa23f732d84dad054b02a61f530e6/pkg/git/git.go#L22
- https://vuln.go.dev/ID/GO-2024-2863.json
Feedback
This report is unreviewed. It was automatically generated from a third-party source and its details have not been verified by the Go team.
See anything missing or incorrect?
Suggest an edit to this report.