Skip to content

CVE-2022-0227 High Vulnerability : github.com/emicklei/go-restful/v3 go-restful v3.9.0 #1061

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
liangcorp opened this issue Feb 1, 2023 · 2 comments
Labels
area/dependency Issues or PRs related to dependency changes

Comments

@liangcorp
Copy link

liangcorp commented Feb 1, 2023

github.com/emicklei/go-restful/v3 module prior to v3.10.0 is vulnerable to Authentication Bypass by Primary Weakness. There is an inconsistency in how go-restful parses URL paths. This inconsistency could lead to several security check bypass in a complex system.

Current version in go.mod:

github.com/emicklei/go-restful/v3 v3.9.0 
@liangcorp liangcorp changed the title CP4NA Vulnerability : github.com/emicklei/go-restful/v3 - PRISMA-2022-0227 CVE Vulnerability : github.com/emicklei/go-restful/v3 - PRISMA-2022-0227 Feb 1, 2023
@liangcorp liangcorp changed the title CVE Vulnerability : github.com/emicklei/go-restful/v3 - PRISMA-2022-0227 CVE-2022-0227 Vulnerability : github.com/emicklei/go-restful/v3 - PRISMA-2022-0227 Feb 1, 2023
@liangcorp liangcorp changed the title CVE-2022-0227 Vulnerability : github.com/emicklei/go-restful/v3 - PRISMA-2022-0227 CVE-2022-0227 High Vulnerability : github.com/emicklei/go-restful/v3 go-restful v3.8.0 Feb 1, 2023
@liangcorp liangcorp changed the title CVE-2022-0227 High Vulnerability : github.com/emicklei/go-restful/v3 go-restful v3.8.0 CVE-2022-0227 High Vulnerability : github.com/emicklei/go-restful/v3 go-restful v3.9.0 May 19, 2023
@grokspawn grokspawn added dependencies Pull requests that update a dependency file area/dependency Issues or PRs related to dependency changes and removed dependencies Pull requests that update a dependency file labels Jun 9, 2023
@mrmadira
Copy link

I am another consumer and I am looking forward to a fix for this one as well, as it if getting flagged in our scan reports

@Neo2308
Copy link
Contributor

Neo2308 commented Jan 9, 2024

Fixed as part of #1134

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area/dependency Issues or PRs related to dependency changes
Projects
None yet
Development

No branches or pull requests

5 participants