Credentials provided via the new GOAUTH feature were not being properly segmented by domain, allowing a malicious server to request credentials they should not have access to. By default, unless otherwise set, this only affected credentials stored in the users .netrc file.
{ "binaries": [ { "binary_name": "golang-1.8", "binary_version": "1.8.3-2ubuntu1.18.04.1" }, { "binary_name": "golang-1.8-go", "binary_version": "1.8.3-2ubuntu1.18.04.1" }, { "binary_name": "golang-1.8-go-shared-dev", "binary_version": "1.8.3-2ubuntu1.18.04.1" }, { "binary_name": "golang-1.8-src", "binary_version": "1.8.3-2ubuntu1.18.04.1" }, { "binary_name": "libgolang-1.8-std1", "binary_version": "1.8.3-2ubuntu1.18.04.1" } ] }