{"id":"GHSA-5v95-v8c8-3rh6","summary":"Privilege escalation in rbac","details":"### Impact\nUsing a carefully crafted request or malicious proxy, a user with `UserWrite` permissions could create another user with higher privileges than their own due to insufficient checks on the allowed set of permissions. The event would be captured in the Event Log.\n\n### Patches\nThe issue has been fixed in 0.24.0 and 0.23.1.\n\n### Workarounds\nFor users who are unable to upgrade, we recommend auditing users who have `UserWrite` permissions and regularly reviewing the Event Log for malicious activity.\n\n### Kudos\nThank you to Michael Mazzolini (Ethical Hacker at WHO) for finding and disclosing this vulnerability.","aliases":["CVE-2021-22538","GO-2022-0798"],"modified":"2026-07-08T06:29:54.377303904Z","published":"2021-05-21T14:32:55Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2021-05-20T22:26:21Z","nvd_published_at":"2021-03-31T21:15:00Z","cwe_ids":["CWE-276"]},"references":[{"type":"WEB","url":"https://github.com/google/exposure-notifications-verification-server/security/advisories/GHSA-5v95-v8c8-3rh6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-22538"},{"type":"WEB","url":"https://github.com/google/exposure-notifications-verification-server/commit/eb8cf40b12dbe79304f1133c06fb73419383cd95"},{"type":"WEB","url":"https://github.com/google/exposure-notifications-verification-server/releases/tag/v0.23.1"},{"type":"WEB","url":"https://github.com/google/exposure-notifications-verification-server/releases/tag/v0.24.0"}],"affected":[{"package":{"name":"github.com/google/exposure-notifications-verification-server","ecosystem":"Go","purl":"pkg:golang/github.com/google/exposure-notifications-verification-server"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.23.1"}]}],"database_specific":{"last_known_affected_version_range":"\u003c 0.23.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/05/GHSA-5v95-v8c8-3rh6/GHSA-5v95-v8c8-3rh6.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}