Back

CRITICAL

Authorization Bypass Through User-Controlled Key in emicklei/go-restful

Published Jun 6, 2022

Description

Authorization Bypass Through User-Controlled Key in GitHub repository emicklei/go-restful prior to v3.8.0.

Affected products

Remediation

Red Hat statement

The go-restful package is a transitive dependency which is being pulled with k8s.io/api and not directly being used anywhere in OpenShift Container Platform (OCP), OpenShift Container Storage, OpenShift Data Foundation, OpenShift Do and OpenShift Pipelines, hence these components are marked as 'Will not fix' or even "Not affected".

Metrics

References (28)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner @huntrdev
Published Jun 6, 2022
Updated Aug 3, 2024
Reserved Jun 6, 2022
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jun 8, 2022
GHSA-R48Q-9G5R-8Q2H