216.73.217.22

CVE-2024-45340

· Published 28/01/2025 02:15 · Modified 28/01/2025 16:15

Labels: CVE-2024-45340 2025-01-28CVE-2024-45340[email protected]

Essential information

Published
28/01/2025 02:15
Modified
28/01/2025 16:15
Author
Creator
CVSS
8.8 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

Credentials provided via the new GOAUTH feature were not being properly segmented by domain, allowing a malicious server to request credentials they should not have access to. By default, unless otherwise set, this only affected credentials stored in the users .netrc file.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

References