Improper authorization control for web services In toolchain
Description
Incorrect access control in the go command in cmd/go/internal/modfetch Incorrect access control is possible in the go command.
The go command can misinterpret branch names that falsely appear to be version tags. This can lead to incorrect access control if an actor is authorized to create branches but not tags.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
go | 1.16.14 | ||
debian 11 | 1.15.15-1~deb11u3 | ||
rpm rhel7 | - | - | |
rpm rhel8 | 0:1.17.7-1.module+el8.6.0+14297+32a15e19 |
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1. 2. 3. 4. 5.