logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2024-23840

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2024-23840

Description:
GoReleaser builds Go binaries for several platforms, creates a GitHub release and then pushes a Homebrew formula to a tap repository. `goreleaser release --debug` log shows secret values used in the in the custom publisher. This vulnerability is fixed in 1.24.0.
Last updated date:
02/05/2024
Type:
exploit
Confidence:
HIGH
Date of publishing:
02/05/2024
Reference url to background

https://github.com/goreleaser/goreleaser/security/advisories/GHSA-h3q2-8whx-c29h

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy