Skip to content

x/vulndb: potential Go vuln in github.com/nanobox-io/golang-nanoauth: GHSA-hrm3-3xm6-x33h #1227

Closed
@GoVulnBot

Description

@GoVulnBot

In GitHub Security Advisory GHSA-hrm3-3xm6-x33h, there is a vulnerability in the following Go packages or modules:

Unit Fixed Vulnerable Ranges
github.com/nanobox-io/golang-nanoauth >= 0.0.0-20160722212129-ac0cc4484ad4, < 0.0.0-20200131131040-063a3fb69896

Cross references:

See doc/triage.md for instructions on how to triage this report.

modules:
  - module: TODO
    versions:
      - introduced: TODO (earliest fixed "", vuln range ">= 0.0.0-20160722212129-ac0cc4484ad4,
            < 0.0.0-20200131131040-063a3fb69896")
    packages:
      - package: github.com/nanobox-io/golang-nanoauth
description: Authentication is globally bypassed in github.com/nanobox-io/golang-nanoauth
    between v0.0.0-20160722212129-ac0cc4484ad4 and v0.0.0-20200131131040-063a3fb69896
    if ListenAndServe is called with an empty token.
cves:
  - CVE-2020-36569
ghsas:
  - GHSA-hrm3-3xm6-x33h

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions