golang.org Go
cpe:2.3:a:golang:go:*:*:*:*:*:*:*
- >= 1.24.0-0, < 1.24.0-rc.2
A vulnerability exists in the Go programming language's command-line tool, specifically in the GOAUTH feature, where credentials were not properly isolated by domain. This flaw allowed a malicious server to access credentials that should have been restricted. By default, this issue impacted credentials stored in the user's .netrc file.
Exploitation of this vulnerability could lead to unauthorized access to sensitive credentials, allowing malicious servers to request and potentially misuse credentials that belong to other domains.
Users can upgrade to Go version 1.24.0-rc.2 or later, where this vulnerability has been fixed. Instructions for downloading this version are available on the Go website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.