MEDIUM5.3
GHSA-5mmw-p5qv-w3x5
Always incorrect control flow in github.com/mojocn/base64Captcha
Quick fix
GHSA-5mmw-p5qv-w3x5 — github.com/mojocn/base64Captcha: upgrade to the fixed version with the command below.
go get github.com/mojocn/base64Captcha@v1.3.6Details
When using the default implementation of Verify to check a Captcha, verification can be bypassed. For example, if the first parameter is a non-existent id, the second parameter is an empty string, and the third parameter is true, the function will always consider the Captcha to be correct.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/mojocn/base64Captcha
Introduced in:
0Fixed in: 1.3.6Fix
go get github.com/mojocn/base64Captcha@v1.3.6References
- https://nvd.nist.gov/vuln/detail/CVE-2023-45292[ADVISORY]
- https://github.com/mojocn/base64Captcha/issues/120[WEB]
- https://github.com/mojocn/base64Captcha/commit/5ab86bd6f333aad3936f912fc52b411168dcd4a7[WEB]
- https://github.com/mojocn/base64Captcha/commit/9b11012caca58925f1e47c770f79f2fa47e3ad13[WEB]
- https://github.com/mojocn/base64Captcha[PACKAGE]
- https://pkg.go.dev/vuln/GO-2023-2386[WEB]