Hi,
The following vulnerability was published for golang-github-cli-go-gh-v2.
CVE-2024-53859[0]:
| go-gh is a Go module for interacting with the `gh` utility and the
| GitHub API from the command line. A security vulnerability has been
| identified in `go-gh` that could leak authentication tokens intended
| for GitHub hosts to non-GitHub hosts when within a codespace. `go-
| gh` sources authentication tokens from different environment
| variables depending on the host involved: 1. `GITHUB_TOKEN`,
| `GH_TOKEN` for GitHub.com and ghe.com and 2.
| `GITHUB_ENTERPRISE_TOKEN`, `GH_ENTERPRISE_TOKEN` for GitHub
| Enterprise Server. Prior to version `2.11.1`, `auth.TokenForHost`
| could source a token from the `GITHUB_TOKEN` environment variable
| for a host other than GitHub.com or ghe.com when within a codespace.
| In version `2.11.1`, `auth.TokenForHost` will only source a token
| from the `GITHUB_TOKEN` environment variable for GitHub.com or
| ghe.com hosts. Successful exploitation could send authentication
| token to an unintended host. This issue has been addressed in
| version 2.11.1 and all users are advised to upgrade. Users are also
| advised to regenerate authentication tokens and to review their
| personal security log and any relevant audit logs for actions
| associated with their account or enterprise.
https://github.com/cli/go-gh/security/advisories/GHSA-55v3-xh23-96gh
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2024-53859
https://www.cve.org/CVERecord?id=CVE-2024-53859
Please adjust the affected versions in the BTS as needed.