CVE-2020-36569
Severity CVSS v4.0:
Pending analysis
Type:
CWE-287
Authentication Issues
Publication date:
27/12/2022
Last modified:
11/04/2025
Description
Authentication is globally bypassed in github.com/nanobox-io/golang-nanoauth between v0.0.0-20160722212129-ac0cc4484ad4 and v0.0.0-20200131131040-063a3fb69896 if ListenAndServe is called with an empty token.
Impact
Base Score 3.x
9.10
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:digitalocean:golang-nanoauth:*:*:*:*:*:go:*:* | 2016-07-22 (including) | 2020-01-31 (including) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://github.com/nanobox-io/golang-nanoauth/commit/063a3fb69896acf985759f0fe3851f15973993f3
- https://github.com/nanobox-io/golang-nanoauth/pull/5
- https://pkg.go.dev/vuln/GO-2020-0004
- https://github.com/nanobox-io/golang-nanoauth/commit/063a3fb69896acf985759f0fe3851f15973993f3
- https://github.com/nanobox-io/golang-nanoauth/pull/5
- https://pkg.go.dev/vuln/GO-2020-0004



