LOW
Race condition in github.com/ntbosscher/gobase
Published Dec 27, 2022
3.7
LOWCVSS 3.1
EPSS 0.35%
Description
A race condition can cause incorrect HTTP request routing.
Affected products
- Vendor Github.com/ntbosscher/gobase Product Github.com/ntbosscher/gobase/auth/httpauth Defaultunaffected
- Version 0StatusaffectedConstraints<0.7.2
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Github.com/ntbosscher/gobase | Github.com/ntbosscher/gobase/auth/httpauth | unaffected |
|
- < 0.7.2
No data.
No Red Hat product state for this CVE.
github.com/ntbosscher/gobase
Go
Introduced 0 Fixed 0.7.2
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/ntbosscher/gobase | 0 | 0.7.2 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-7495 Advisory
- https://github.com/advisories/GHSA-h2x7-2ff6-v32p Advisory
- https://github.com/ntbosscher/gobase/commit/a8d40bce9c429d324122d18c446924dab809e812 PatchThird Party Advisory
- https://github.com/ntbosscher/gobase/security/advisories/GHSA-h2x7-2ff6-v32p
- https://nvd.nist.gov/vuln/detail/CVE-2022-2583
- https://pkg.go.dev/vuln/GO-2022-0400 PatchThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-7495 | Advisory | |
| https://github.com/advisories/GHSA-h2x7-2ff6-v32p | Advisory | |
| https://github.com/ntbosscher/gobase/commit/a8d40bce9c429d324122d18c446924dab809e812 | PatchThird Party Advisory | |
| https://github.com/ntbosscher/gobase/security/advisories/GHSA-h2x7-2ff6-v32p | ||
| https://nvd.nist.gov/vuln/detail/CVE-2022-2583 | ||
| https://pkg.go.dev/vuln/GO-2022-0400 | PatchThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Go
Published Dec 27, 2022
Updated Apr 11, 2025
Reserved Jul 29, 2022
Link CVE-2022-2583
CISA Vulnrichment
Updated Apr 11, 2025
ENISA EUVD
EUVD-2022-7495 GHSA-H2X7-2FF6-V32P Assigner Go
Published Dec 27, 2022
Updated Apr 11, 2025
Exploited since n/a
Link EUVD-2022-7495