—
GO-2022-0786
Authentication Bypass in hydra in github.com/ory/hydra
Quick fix
GO-2022-0786 — github.com/ory/hydra: upgrade to the fixed version with the command below.
go get github.com/ory/hydra@v1.4.0Details
Authentication Bypass in hydra in github.com/ory/hydra
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/ory/hydra/security/advisories/GHSA-3p3g-vpw6-4w66[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2020-5300[ADVISORY]
- https://github.com/ory/hydra/commit/700d17d3b7d507de1b1d459a7261d6fb2571ebe3[FIX]
- https://github.com/ory/hydra/releases/tag/v1.4.0[WEB]
- https://openid.net/specs/openid-connect-core-1_0.html#ClientAuthentication[WEB]