{"id":"GO-2022-0964","summary":"SFTPGo vulnerable to recovery codes abuse in github.com/drakkan/sftpgo","details":"SFTPGo vulnerable to recovery codes abuse in github.com/drakkan/sftpgo","aliases":["CVE-2022-36071","GHSA-54qx-8p8w-xhg8"],"modified":"2026-03-03T04:52:33.164973Z","published":"2024-08-21T16:03:21Z","database_specific":{"review_status":"UNREVIEWED","url":"https://pkg.go.dev/vuln/GO-2022-0964"},"references":[{"type":"ADVISORY","url":"https://github.com/drakkan/sftpgo/security/advisories/GHSA-54qx-8p8w-xhg8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-36071"},{"type":"REPORT","url":"https://github.com/drakkan/sftpgo/issues/965"}],"affected":[{"package":{"name":"github.com/drakkan/sftpgo","ecosystem":"Go","purl":"pkg:golang/github.com/drakkan/sftpgo"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2022-0964.json"}},{"package":{"name":"github.com/drakkan/sftpgo/v2","ecosystem":"Go","purl":"pkg:golang/github.com/drakkan/sftpgo/v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.2.0"},{"fixed":"2.3.4"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2022-0964.json"}}],"schema_version":"1.7.3"}