—
GO-2023-1955
Dapr API token authentication bypass in HTTP endpoints in github.com/dapr/dapr
Quick fix
GO-2023-1955 — github.com/dapr/dapr: upgrade to the fixed version with the command below.
go get github.com/dapr/dapr@v1.10.9Details
Dapr API token authentication bypass in HTTP endpoints in github.com/dapr/dapr
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/dapr/dapr/security/advisories/GHSA-59m6-82qm-vqgj[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2023-37918[ADVISORY]
- https://github.com/dapr/dapr/commit/83ca1abb11ffe34211db55dcd36d96b94252827a[FIX]
- https://github.com/dapr/dapr/commit/99d6799c97b79397443c8c96737c9b893126a1ae[FIX]
- https://docs.dapr.io/operations/security/api-token[WEB]