GO-2020-0004

Source
https://vuln.go.dev/ID/GO-2020-0004.json
Aliases
  • CVE-2020-36569
Published
2021-04-14T20:04:52Z
Modified
2022-11-21T19:50:45Z
Details

If any of the ListenAndServe functions are called with an empty token, token authentication is disabled globally for all listeners.

Also, a minor timing side channel was present allowing attackers with very low latency and able to make a lot of requests to potentially recover the token.

References

Affected packages

Go / github.com/nanobox-io/golang-nanoauth

github.com/nanobox-io/golang-nanoauth

Affected ranges

Type
SEMVER
Events
Introduced
0.0.0-20160722212129-ac0cc4484ad4
Fixed
0.0.0-20200131131040-063a3fb69896

Affected versions

Ecosystem specific

{
    "imports": [
        {
            "symbols": [
                "Auth.ListenAndServe",
                "Auth.ListenAndServeTLS",
                "Auth.ServerHTTP",
                "ListenAndServe",
                "ListenAndServeTLS"
            ],
            "path": "github.com/nanobox-io/golang-nanoauth"
        }
    ]
}

Database specific

{
    "url": "https://pkg.go.dev/vuln/GO-2020-0004"
}