VDB
Sign up
HIGH8.8

GHSA-r6qh-j42j-pw64

Beego privilege escalation vulnerability

Quick fix

GHSA-r6qh-j42j-pw64 — github.com/beego/beego/v2: upgrade to the fixed version with the command below.

go get github.com/beego/beego/v2@v2.2.1

Details

An issue in beego v.2.2.0 and before allows a remote attacker to escalate privileges via the `sendMail` function located in the `beego/core/logs/smtp.go` file.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/beego/beego/v2
Introduced in: 0Fixed in: 2.2.1
Fixgo get github.com/beego/beego/v2@v2.2.1

References