Vulnerability Report: GO-2021-0107
- CVE-2021-4236, GHSA-5gjg-jgh4-gppm, and 1 more
- Affects: github.com/ecnepsnai/web
- Published: Jul 28, 2021
- Modified: May 20, 2024
Web Sockets do not execute any AuthenticateMethod methods which may be set, leading to a nil pointer dereference if the returned UserData pointer is assumed to be non-nil, or authentication bypass. This issue only affects WebSockets with an AuthenticateMethod hook. Request handlers that do not explicitly use WebSockets are not vulnerable.
Affected Packages
-
PathGo VersionsSymbols
-
from v1.4.0 before v1.5.2
Aliases
References
- https://github.com/ecnepsnai/web/commit/5a78f8d5c41ce60dcf9f61aaf47a7a8dc3e0002f
- https://vuln.go.dev/ID/GO-2021-0107.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.