CRITICAL9.1
GHSA-hrm3-3xm6-x33h
golang-nanoauth authentication bypass vulnerability
Quick fix
GHSA-hrm3-3xm6-x33h — github.com/nanobox-io/golang-nanoauth: upgrade to the fixed version with the command below.
go get github.com/nanobox-io/golang-nanoauth@v0.0.0-20200131131040-063a3fb69896Details
Authentication is globally bypassed in github.com/nanobox-io/golang-nanoauth between v0.0.0-20160722212129-ac0cc4484ad4 and v0.0.0-20200131131040-063a3fb69896 if ListenAndServe is called with an empty token.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/nanobox-io/golang-nanoauth
Introduced in:
0.0.0-20160722212129-ac0cc4484ad4Fixed in: 0.0.0-20200131131040-063a3fb69896Fix
go get github.com/nanobox-io/golang-nanoauth@v0.0.0-20200131131040-063a3fb69896References
- https://nvd.nist.gov/vuln/detail/CVE-2020-36569[ADVISORY]
- https://github.com/nanobox-io/golang-nanoauth/pull/5[WEB]
- https://github.com/nanobox-io/golang-nanoauth/commit/063a3fb69896acf985759f0fe3851f15973993f3[WEB]
- https://github.com/nanobox-io/golang-nanoauth[PACKAGE]
- https://pkg.go.dev/vuln/GO-2020-0004[WEB]