CVE Published: 27/12/2022 |
CVE Updated: 04/08/2024 |
CVE Year: 2020 Source: Go |
Vendor: github.com/nanobox-io/golang-nanoauth |
Product: github.com/nanobox-io/golang-nanoauth Status : PUBLISHED
CVE-2020-36569 Description
Authentication is globally bypassed in github.com/nanobox-io/golang-nanoauth between v0.0.0-20160722212129-ac0cc4484ad4 and v0.0.0-20200131131040-063a3fb69896 if ListenAndServe is called with an empty token.