5.5
CVSSv3

CVE-2024-23840

Published: 30/01/2024 Updated: 05/02/2024
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

GoReleaser builds Go binaries for several platforms, creates a GitHub release and then pushes a Homebrew formula to a tap repository. `goreleaser release --debug` log shows secret values used in the in the custom publisher. This vulnerability is fixed in 1.24.0.

Vulnerable Product Search on Vulmon Subscribe to Product

goreleaser goreleaser 1.23.0

Vendor Advisories

Description<!---->A flaw was found in GoReleaser This package log shows secret values that are supposed to be hidden when using --debugA flaw was found in GoReleaser This package log shows secret values that are supposed to be hidden when using --debug ...