CVE-2024-53859 is a security vulnerability in the go-gh Go module, affecting its use within codespaces. This flaw could lead to the unintended leakage of authentication tokens, specifically those designated for GitHub hosts, to non-GitHub hosts. The vulnerability stems from auth.TokenForHost incorrectly sourcing tokens from the GITHUB_TOKEN environment variable for non-GitHub.com or ghe.com hosts. The vulnerability carries a CVSS score of 7.5 (HIGH), indicating a significant risk. It is a network-based attack with low attack complexity, requiring no user interaction, and could result in high confidentiality impact by exposing sensitive authentication tokens. As of now, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage are minimal, suggesting low public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.11.1CPE matchmatch criteria | cpe:2.3:a:cli:go-gh:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.