Vulnerability Report: GO-2025-3383
standard library- CVE-2024-45340
- Affects: cmd/go
- Published: Jan 28, 2025
- Modified: Jan 30, 2025
Credentials provided via the new GOAUTH feature were not being properly segmented by domain, allowing a malicious server to request credentials they should not have access to. By default, unless otherwise set, this only affected credentials stored in the users .netrc file.
Affected Packages
-
PathGo VersionsSymbols
-
from go1.24.0-0 before go1.24.0-rc.2all symbols
Aliases
References
- https://go.dev/cl/643097
- https://go.dev/issue/71249
- https://groups.google.com/g/golang-dev/c/CAWXhan3Jww/m/bk9LAa-lCgAJ
- https://vuln.go.dev/ID/GO-2025-3383.json
Credits
- Juho Forsén of Mattermost
Feedback
See anything missing or incorrect?
Suggest an edit to this report.