Lucene search

K
osvGoogleOSV:GO-2021-0107
HistoryJul 28, 2021 - 6:08 p.m.

Panic or authentication bypass in github.com/ecnepsnai/web

2021-07-2818:08:05
Google
osv.dev
18

9.7 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

54.5%

Web Sockets do not execute any AuthenticateMethod methods which may be set, leading to a nil pointer dereference if the returned UserData pointer is assumed to be non-nil, or authentication bypass.

This issue only affects WebSockets with an AuthenticateMethod hook. Request handlers that do not explicitly use WebSockets are not vulnerable.

9.7 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

54.5%

Related for OSV:GO-2021-0107