#VU103456 Information disclosure in Go programming language - CVE-2024-45340
Published: January 30, 2025
Go programming language
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to incorrect segmentation of credentials by domain names in the GOAUTH feature. A remote attacker can trick the client into connecting to a malicious server and obtain credentials stored in the users .netrc file.