—
GO-2021-0107
Panic or authentication bypass in github.com/ecnepsnai/web
Quick fix
GO-2021-0107 — github.com/ecnepsnai/web: upgrade to the fixed version with the command below.
go get github.com/ecnepsnai/web@v1.5.2Details
Web Sockets do not execute any AuthenticateMethod methods which may be set, leading to a nil pointer dereference if the returned UserData pointer is assumed to be non-nil, or authentication bypass.
This issue only affects WebSockets with an AuthenticateMethod hook. Request handlers that do not explicitly use WebSockets are not vulnerable.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/ecnepsnai/web
Introduced in:
1.4.0Fixed in: 1.5.2Fix
go get github.com/ecnepsnai/web@v1.5.2