Description
Web Sockets do not execute any AuthenticateMethod methods which may be set, leading to a nil pointer dereference if the returned UserData pointer is assumed to be non-nil, or authentication bypass. This issue only affects WebSockets with an AuthenticateMethod hook. Request handlers that do not explicitly use WebSockets are not vulnerable.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-7668 | Web Sockets do not execute any AuthenticateMethod methods which may be set, leading to a nil pointer dereference if the returned UserData pointer is assumed to be non-nil, or authentication bypass. This issue only affects WebSockets with an AuthenticateMethod hook. Request handlers that do not explicitly use WebSockets are not vulnerable. |
Github GHSA |
GHSA-jpgg-cp2x-qrw3 | ecnepsnai/web vulnerable to Uncontrolled Resource Consumption |
Github GHSA |
GHSA-5gjg-jgh4-gppm | Websocket requests did not call AuthenticateMethod |
References
History
Fri, 11 Apr 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Go
Published:
Updated: 2025-04-11T16:20:55.821Z
Reserved: 2022-07-29T19:01:04.923Z
Link: CVE-2021-4236
Updated: 2024-08-03T17:23:10.220Z
Status : Modified
Published: 2022-12-27T22:15:12.013
Modified: 2025-04-11T17:15:35.677
Link: CVE-2021-4236
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA