CVE-2020-36569
27.12.2022, 22:15
Authentication is globally bypassed in github.com/nanobox-io/golang-nanoauth between v0.0.0-20160722212129-ac0cc4484ad4 and v0.0.0-20200131131040-063a3fb69896 if ListenAndServe is called with an empty token.Enginsight
Vendor | Product | Version |
---|---|---|
digitalocean | golang-nanoauth | 2016-07-22 ≤ 𝑥 ≤ 2020-01-31 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References