—
GO-2022-0906
Authentication Bypass in tyk-identity-broker in github.com/TykTechnologies/tyk-identity-broker
Quick fix
GO-2022-0906 — github.com/TykTechnologies/tyk-identity-broker: upgrade to the fixed version with the command below.
go get github.com/TykTechnologies/tyk-identity-broker@v1.1.1Details
Authentication Bypass in tyk-identity-broker in github.com/TykTechnologies/tyk-identity-broker
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/TykTechnologies/tyk-identity-broker
Introduced in:
0Fixed in: 1.1.1Fix
go get github.com/TykTechnologies/tyk-identity-broker@v1.1.1References
- https://github.com/advisories/GHSA-599h-8wpj-75xj[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2021-23365[ADVISORY]
- https://github.com/TykTechnologies/tyk-identity-broker/commit/243092965b0f93a95a14cb882b5b9a3df61dd5c0[FIX]
- https://github.com/TykTechnologies/tyk-identity-broker/commit/46f70420e0911e4e8b638575e29d394c227c75d0[FIX]
- https://github.com/TykTechnologies/tyk-identity-broker/pull/147[FIX]
- https://github.com/TykTechnologies/tyk-identity-broker/releases/tag/v1.1.1[WEB]
- https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMTYKTECHNOLOGIESTYKIDENTITYBROKER-1089720[WEB]