CVE-2024-45340 Details
Description
Credentials provided via the new GOAUTH feature were not being properly segmented by domain, allowing a malicious server to request credentials they should not have access to. By default, unless otherwise set, this only affected credentials stored in the users .netrc file.
A vulnerability exists in the Go programming language's command-line tool, specifically in the GOAUTH feature, where credentials were not properly isolated by domain. This flaw allowed a malicious server to access credentials that should have been restricted. By default, this issue impacted credentials stored in the user's .netrc file.
Users can upgrade to Go version 1.24.0-rc.2 or later, where this vulnerability has been fixed. Instructions for downloading this version are available on the Go website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 28, 2025CISA-ADP
Assessed Jan 28, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://go.dev/cl/643097 | [email protected] | Source CodeVendor |
| https://go.dev/issue/71249 | [email protected] | Issue TrackingTechnical DescriptionVendor |
| https://groups.google.com/g/golang-dev/c/CAWXhan3Jww/m/bk9LAa-lCgAJ | [email protected] | BundleMailing ListRemedyVendor |
| https://pkg.go.dev/vuln/GO-2025-3383 | [email protected] | AdvisoryBundleVendor |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| golang.org Go | >= 1.24.0-0, < 1.24.0-rc.2 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 28, 2025 | CVE Modified | CISA-ADP |
| Jan 28, 2025 | New CVE Received | [email protected] |
Volerion