{"id":"GO-2020-0004","summary":"Authentication bypass in github.com/nanobox-io/golang-nanoauth","details":"If any of the ListenAndServe functions are called with an empty token, token authentication is disabled globally for all listeners.\n\nAlso, a minor timing side channel was present allowing attackers with very low latency and able to make many requests to potentially recover the token.","aliases":["CVE-2020-36569","GHSA-hrm3-3xm6-x33h"],"modified":"2024-05-20T16:03:47Z","published":"2021-04-14T20:04:52Z","database_specific":{"review_status":"REVIEWED","url":"https://pkg.go.dev/vuln/GO-2020-0004"},"references":[{"type":"FIX","url":"https://github.com/nanobox-io/golang-nanoauth/pull/5"},{"type":"FIX","url":"https://github.com/nanobox-io/golang-nanoauth/commit/063a3fb69896acf985759f0fe3851f15973993f3"}],"affected":[{"package":{"name":"github.com/nanobox-io/golang-nanoauth","ecosystem":"Go","purl":"pkg:golang/github.com/nanobox-io/golang-nanoauth"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.0.0-20160722212129-ac0cc4484ad4"},{"fixed":"0.0.0-20200131131040-063a3fb69896"}]}],"ecosystem_specific":{"imports":[{"path":"github.com/nanobox-io/golang-nanoauth","symbols":["Auth.ListenAndServe","Auth.ListenAndServeTLS","Auth.ServeHTTP","ListenAndServe","ListenAndServeTLS"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2020-0004.json"}}],"schema_version":"1.7.3","credits":[{"name":"@bouk"}]}