Vulnerability Report: GO-2021-0107
- CVE-2021-4236, GHSA-5gjg-jgh4-gppm, and 1 more
- Affects: github.com/ecnepsnai/web
- Published: Jul 28, 2021
- Modified: Jun 12, 2023
Web Sockets do not execute any AuthenticateMethod methods which may be set, leading to a nil pointer dereference if the returned UserData pointer is assumed to be non-nil, or authentication bypass. This issue only affects WebSockets with an AuthenticateMethod hook. Request handlers that do not explicitly use WebSockets are not vulnerable.
from v1.4.0 before v1.5.2