github.com/goreleaser/goreleaser/v2 is vulnerable to Insertion of Sensitive Information into Log File
18
Low Risk
Affected versions of goreleaser are vulnerable to insertion of sensitive information into log files due to insufficient sanitization of values written to logs. Under certain conditions, authentication tokens or other sensitive configuration values may be included in log output, potentially exposing secrets to users who have access to build or CI logs. An attacker with access to these logs could retrieve the exposed credentials and use them to access external services or repositories.
You are affected if you are using a version that falls within the vulnerable range.
github.com/goreleaser/goreleaser/v2 is vulnerable to Insertion of Sensitive Information into Log File in versions 2.0.0 - 2.13.3.
Upgrade the github.com/goreleaser/goreleaser/v2 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant