CVE-2020-36569: Authentication bypass in github.com/nanobox-io/golang-nanoauth
Authentication is globally bypassed in github.com/nanobox-io/golang-nanoauth between v0.0.0-20160722212129-ac0cc4484ad4 and v0.0.0-20200131131040-063a3fb69896 if ListenAndServe is called with an empty token.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-36569?
CVE-2020-36569 is considered a high severity vulnerability due to the global authentication bypass it introduces.
How do I fix CVE-2020-36569?
To fix CVE-2020-36569, upgrade to a version of golang-nanoauth that is after v0.0.0-20200131131040-063a3fb69896.
What versions are affected by CVE-2020-36569?
CVE-2020-36569 affects versions of golang-nanoauth between v0.0.0-20160722212129-ac0cc4484ad4 and v0.0.0-20200131131040-063a3fb69896.
Can CVE-2020-36569 be exploited remotely?
Yes, CVE-2020-36569 can be exploited remotely due to the global authentication bypass.
What platforms are impacted by CVE-2020-36569?
CVE-2020-36569 impacts any application using vulnerable versions of golang-nanoauth on platforms where it is deployed.