CVE-2020-36569

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
27/12/2022
Last modified:
11/04/2025

Description

Authentication is globally bypassed in github.com/nanobox-io/golang-nanoauth between v0.0.0-20160722212129-ac0cc4484ad4 and v0.0.0-20200131131040-063a3fb69896 if ListenAndServe is called with an empty token.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:digitalocean:golang-nanoauth:*:*:*:*:*:go:*:* 2016-07-22 (including) 2020-01-31 (including)