QID 982434
QID 982434: Go (go) Security Update for github.com/google/exposure-notifications-verification-server (GHSA-5v95-v8c8-3rh6)
Security update has been released for github.com/google/exposure-notifications-verification-server to fix the vulnerability.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Using a carefully crafted request or malicious proxy, a user with `UserWrite` permissions could create another user with higher privileges than their own due to insufficient checks on the allowed set of permissions. The event would be captured in the Event Log.
Solution
The issue has been fixed in 0.24.0 and 0.23.1.Workaround:
For users who are unable to upgrade, we recommend auditing users who have `UserWrite` permissions and regularly reviewing the Event Log for malicious activity.
For users who are unable to upgrade, we recommend auditing users who have `UserWrite` permissions and regularly reviewing the Event Log for malicious activity.
Vendor References
- GHSA-5v95-v8c8-3rh6 -
github.com/advisories/GHSA-5v95-v8c8-3rh6
CVEs related to QID 982434
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-5v95-v8c8-3rh6 | github.com/google/exposure-notifications-verification-server |
|