SCA: security update for github.com/cli/go-gh/v2 (GHSA-55v3-xh23-96gh)

high Tenable Cloud Security Plugin ID 410602

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- go-gh is a Go module for interacting with the `gh` utility and the GitHub API from the command line. A
security vulnerability has been identified in `go-gh` that could leak authentication tokens intended for
GitHub hosts to non-GitHub hosts when within a codespace. `go-gh` sources authentication tokens from
different environment variables depending on the host involved: 1. `GITHUB_TOKEN`, `GH_TOKEN` for
GitHub.com and ghe.com and 2. `GITHUB_ENTERPRISE_TOKEN`, `GH_ENTERPRISE_TOKEN` for GitHub Enterprise
Server. Prior to version `2.11.1`, `auth.TokenForHost` could source a token from the `GITHUB_TOKEN`
environment variable for a host other than GitHub.com or ghe.com when within a codespace. In version
`2.11.1`, `auth.TokenForHost` will only source a token from the `GITHUB_TOKEN` environment variable for
GitHub.com or ghe.com hosts. Successful exploitation could send authentication token to an unintended
host. This issue has been addressed in version 2.11.1 and all users are advised to upgrade. Users are also
advised to regenerate authentication tokens and to review their personal security log and any relevant
audit logs for actions associated with their account or enterprise. (CVE-2024-53859)

See Also

https://github.com/advisories/GHSA-55v3-xh23-96gh

Plugin Details

Severity: High

ID: 410602

Version: Revision 1.8

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.51

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N

CVSS Score Source: CVE-2024-53859

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 11/27/2024

Vulnerability Publication Date: 11/27/2024

Reference Information

CVE: CVE-2024-53859

cwe: CWE-200