Improper authorization control for web services In github.com/forceu/gokapi
Description
Gokapi has privilege escalation with auth token
Impact
A registered user without privileges to create or modify file requests is able to create a short-lived API key that has the permission to do so.
The user must be registered with Gokapi. If you do not have any other users with access to the admin/upload menu, you are not impacted.
Patches
This CVE is patched in v2.2.3
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
go | 2.2.3 |
Aliases
1. 2. 3. 4. 5.
References
1. 2.