Vulnerability Report: GO-2020-0004
- CVE-2020-36569, GHSA-hrm3-3xm6-x33h
- Affects: github.com/nanobox-io/golang-nanoauth
- Published: Apr 14, 2021
- Modified: Jun 12, 2023
If any of the ListenAndServe functions are called with an empty token, token authentication is disabled globally for all listeners. Also, a minor timing side channel was present allowing attackers with very low latency and able to make many requests to potentially recover the token.
Affected Packages
-
PathVersionsSymbols
-
from v0.0.0-20160722212129-ac0cc4484ad4 before v0.0.0-20200131131040-063a3fb69896
Aliases
References
- https://github.com/nanobox-io/golang-nanoauth/pull/5
- https://github.com/nanobox-io/golang-nanoauth/commit/063a3fb69896acf985759f0fe3851f15973993f3
- https://vuln.go.dev/ID/GO-2020-0004.json
Credits
- @bouk
Feedback
See anything missing or incorrect?
Suggest an edit to this report.