{"id":"CVE-2022-1996","summary":"Authorization Bypass Through User-Controlled Key in emicklei/go-restful","details":"Authorization Bypass Through User-Controlled Key in GitHub repository emicklei/go-restful prior to v3.8.0.","aliases":["GHSA-r48q-9g5r-8q2h","GO-2022-0619"],"modified":"2026-04-02T07:40:23.084545Z","published":"2022-06-06T00:00:00Z","related":["CGA-hg94-jm75-6758","SUSE-SU-2022:3321-1","SUSE-SU-2022:3333-1","SUSE-SU-2022:3334-1","SUSE-SU-2022:3335-1","SUSE-SU-2022:3666-1","SUSE-SU-2022:4606-1","SUSE-SU-2023:4727-1","SUSE-SU-2024:0799-1","SUSE-SU-2024:3221-1","SUSE-SU-2024:4329-1","SUSE-SU-2025:20091-1","openSUSE-SU-2022:10081-1","openSUSE-SU-2022:10094-1","openSUSE-SU-2024:12205-1","openSUSE-SU-2024:12252-1","openSUSE-SU-2024:14081-1","openSUSE-SU-2025:15779-1"],"database_specific":{"cwe_ids":["CWE-639"],"cna_assigner":"@huntrdev","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/1xxx/CVE-2022-1996.json"},"references":[{"type":"WEB","url":"https://huntr.dev/bounties/be837427-415c-4d8c-808b-62ce20aa84f1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/1xxx/CVE-2022-1996.json"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/575BLJ3Y2EQBRNTFR2OSQQ6L2W6UCST3/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OBDD3Q23RCGAGHIXUCWBU6N3S4RNAKXB/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RQXU752ALW53OJAF5MG3WMR5CCZVLWW6/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SO5QC2JFW2PXBWAE27OYYYL5SPFUBHTY/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W56PP46JVZEKCANBKXFKRVSBBRRMCY6V/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z55VUVGO7E5PJFXIOVAY373NZRHBNCI5/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZGQKWD6SE75PFBPFVSZYAKAVXKBZXKWS/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZY2SLWOQR4ZURQ7UBRZ7JIX6H6F5JHJR/"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-1996"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20220923-0005/"},{"type":"FIX","url":"https://github.com/emicklei/go-restful/commit/fd3c327a379ce08c68ef18765bdc925f5d9bad10"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/emicklei/go-restful","events":[{"introduced":"aaadc18f7fcd089ec2589db0d224ba901416392a"},{"fixed":"a2ff8b3f817635c0517a65055c36901e62e96ecb"}]}],"versions":["v3.0.0","v3.0.1","v3.1.0","v3.2.0","v3.3.0","v3.3.1","v3.3.3","v3.4.0","v3.5.0","v3.5.1","v3.5.2","v3.6.0","v3.7.0","v3.7.1","v3.7.2","v3.7.3","v3.7.4"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-1996.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"}]}