PT-2025-2691 · Softwarex+1 · Softwarex+1

Juho Forsén

·

Published

2025-01-13

·

Updated

2025-02-11

·

CVE-2024-45340

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SoftwareX (affected versions not specified)
Description The issue concerns the new GOAUTH feature, where credentials were not properly segmented by domain. This allowed a malicious server to request credentials it should not have access to. By default, this only affected credentials stored in the users' .netrc file.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

BDU:2025-02786
BIT-GOLANG-2024-45340
CVE-2024-45340
ECHO-BA36-854D-9CCC
GO-2025-3383
OPENSUSE-SU-2025:14693-1
OPENSUSE-SU-2025:14710-1
OPENSUSE-SU-2025_0285-1
OPENSUSE-SU-2025_0297-1
OPENSUSE-SU-2025_0429-1
SUSE-SU-2025:0285-1
SUSE-SU-2025:0297-1
SUSE-SU-2025:0429-1
SUSE-SU-2025_0285-1

Affected Products

Softwarex
Suse