Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2024-45340

Published: January 29, 2025Last modified: July 22, 2025

Description

Credentials provided via the new GOAUTH feature were not being properly segmented by domain, allowing a malicious server to request credentials they should not have access to. By default, unless otherwise set, this only affected credentials stored in the users .netrc file.

Severity score breakdown

ParameterValue
Base score8.8
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredLOW
User interactionNONE
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactHIGH
Availability impactHIGH
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSgoNot affected (1.19.7-r0)
StreamgoNot affected (1.24.0-r0)
Hardened Containers23 LTSgoNot affected (1.19.7-r0)
StreamgoNot affected (1.24.0-r0)

References

ON THIS PAGE