QID 996240
Date Published: 2023-12-14
QID 996240: GO (Go) Security Update for github.com/mojocn/base64Captcha (GHSA-5mmw-p5qv-w3x5)
When using the default implementation of Verify to check a Captcha, verification can be bypassed. For example, if the first parameter is a non-existent id, the second parameter is an empty string, and the third parameter is true, the function will always consider the Captcha to be correct.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-5mmw-p5qv-w3x5 for updates and patch information.
Vendor References
- GHSA-5mmw-p5qv-w3x5 -
github.com/advisories/GHSA-5mmw-p5qv-w3x5
CVEs related to QID 996240
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-5mmw-p5qv-w3x5 | github.com/mojocn/base64Captcha |
|