CVE-2024-45340

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
28/01/2025
Last modified:
28/01/2025

Description

Credentials provided via the new GOAUTH feature were not being properly segmented by domain, allowing a malicious server to request credentials they should not have access to. By default, unless otherwise set, this only affected credentials stored in the users .netrc file.