vulndb/data/osv/GO-2023-1630.json

60 строки
1.5 KiB
JSON
Исходник Постоянная ссылка Обычный вид История

data/reports: unexclude 20 reports (3) - data/reports/GO-2023-1590.yaml - data/reports/GO-2023-1592.yaml - data/reports/GO-2023-1596.yaml - data/reports/GO-2023-1607.yaml - data/reports/GO-2023-1612.yaml - data/reports/GO-2023-1613.yaml - data/reports/GO-2023-1614.yaml - data/reports/GO-2023-1615.yaml - data/reports/GO-2023-1616.yaml - data/reports/GO-2023-1617.yaml - data/reports/GO-2023-1618.yaml - data/reports/GO-2023-1619.yaml - data/reports/GO-2023-1620.yaml - data/reports/GO-2023-1622.yaml - data/reports/GO-2023-1627.yaml - data/reports/GO-2023-1628.yaml - data/reports/GO-2023-1629.yaml - data/reports/GO-2023-1630.yaml - data/reports/GO-2023-1633.yaml - data/reports/GO-2023-1639.yaml Updates golang/vulndb#1590 Updates golang/vulndb#1592 Updates golang/vulndb#1596 Updates golang/vulndb#1607 Updates golang/vulndb#1612 Updates golang/vulndb#1613 Updates golang/vulndb#1614 Updates golang/vulndb#1615 Updates golang/vulndb#1616 Updates golang/vulndb#1617 Updates golang/vulndb#1618 Updates golang/vulndb#1619 Updates golang/vulndb#1620 Updates golang/vulndb#1622 Updates golang/vulndb#1627 Updates golang/vulndb#1628 Updates golang/vulndb#1629 Updates golang/vulndb#1630 Updates golang/vulndb#1633 Updates golang/vulndb#1639 Change-Id: I2441a82107b88955ddb98c7d3c55b7b2fe3e3aa7 Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/606783 LUCI-TryBot-Result: Go LUCI <golang-scoped@luci-project-accounts.iam.gserviceaccount.com> Reviewed-by: Damien Neil <dneil@google.com> Auto-Submit: Tatiana Bradley <tatianabradley@google.com>
2024-08-20 19:48:57 +03:00
{
"schema_version": "1.3.1",
"id": "GO-2023-1630",
"modified": "0001-01-01T00:00:00Z",
"published": "0001-01-01T00:00:00Z",
"aliases": [
"CVE-2023-27582",
"GHSA-4g76-w3xw-2x6w"
],
"summary": "Full authentication bypass if SASL authorization username is specified in github.com/foxcpp/maddy",
"details": "Full authentication bypass if SASL authorization username is specified in github.com/foxcpp/maddy",
"affected": [
{
"package": {
"name": "github.com/foxcpp/maddy",
"ecosystem": "Go"
},
"ranges": [
{
"type": "SEMVER",
"events": [
{
"introduced": "0.2.0"
},
{
"fixed": "0.6.3"
}
]
}
],
"ecosystem_specific": {}
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/foxcpp/maddy/security/advisories/GHSA-4g76-w3xw-2x6w"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27582"
},
{
"type": "FIX",
"url": "https://github.com/foxcpp/maddy/commit/55a91a37b71210f34f98f4d327c30308fe24399a"
},
{
"type": "FIX",
"url": "https://github.com/foxcpp/maddy/commit/9f58cb64b39cdc01928ec463bdb198c4c2313a9c"
},
{
"type": "WEB",
"url": "https://github.com/foxcpp/maddy/releases/tag/v0.6.3"
}
],
"database_specific": {
"url": "https://pkg.go.dev/vuln/GO-2023-1630",
"review_status": "UNREVIEWED"
}
}