PT-2024-1505 · Unknown · Goreleaser

Andreaangiolillo

·

Published

2024-01-30

·

Updated

2024-02-13

·

CVE-2024-23840

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions GoReleaser versions prior to 1.24.0
Description The issue is related to information disclosure through log files. When using a custom publisher with goreleaser release --debug, secret values used in the custom publisher are printed to the log. This could allow an attacker to disclose protected information. The estimated number of potentially affected devices worldwide is not specified.
Recommendations For versions prior to 1.24.0, update to version 1.24.0 to resolve the issue. As a temporary workaround, consider avoiding the use of the --debug flag with goreleaser release to minimize the risk of secret values being printed to the log.

Exploit

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

BDU:2024-01013
CVE-2024-23840
GHSA-H3Q2-8WHX-C29H
GO-2024-2482

Affected Products

Goreleaser