Vulnerability Report: GO-2024-2482
- CVE-2024-23840, GHSA-h3q2-8whx-c29h
- Affects: github.com/goreleaser/goreleaser
- Published: Feb 13, 2024
- Modified: May 20, 2024
Secret values can be printed to the --debug log when using a a custom publisher.
For detailed information about this vulnerability, visit https://github.com/goreleaser/goreleaser/security/advisories/GHSA-h3q2-8whx-c29h.
Affected Packages
-
PathGo VersionsSymbols
-
from v1.23.0 before v1.24.0
-
from v1.23.0 before v1.24.0
-
from v1.23.0 before v1.24.0
Aliases
References
- https://github.com/goreleaser/goreleaser/security/advisories/GHSA-h3q2-8whx-c29h
- https://github.com/goreleaser/goreleaser/commit/d5b6a533ca1dc3366983d5d31ee2d2b6232b83c0
- https://vuln.go.dev/ID/GO-2024-2482.json
Credits
- @andreaangiolillo, @caarlos0
Feedback
See anything missing or incorrect?
Suggest an edit to this report.