{"id":"GHSA-28r6-jm5h-mrgg","summary":"Access control bypass in Beego","details":"An issue was discovered in the route lookup process in beego through 2.0.1, allows attackers to bypass access control.","aliases":["CVE-2021-30080","GO-2022-0572"],"modified":"2023-11-01T04:55:15.206719Z","published":"2022-04-06T00:01:30Z","database_specific":{"nvd_published_at":"2022-04-05T16:15:00Z","cwe_ids":[],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2022-04-07T18:13:46Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-30080"},{"type":"WEB","url":"https://github.com/beego/beego/pull/4459"},{"type":"WEB","url":"https://github.com/beego/beego/commit/d5df5e470d0a8ed291930ae802fd7e6b95226519"},{"type":"PACKAGE","url":"https://github.com/beego/beego"},{"type":"WEB","url":"https://pkg.go.dev/vuln/GO-2022-0572"}],"affected":[{"package":{"name":"github.com/beego/beego/v2","ecosystem":"Go","purl":"pkg:golang/github.com/beego/beego/v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.0.0"},{"fixed":"2.0.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-28r6-jm5h-mrgg/GHSA-28r6-jm5h-mrgg.json"}},{"package":{"name":"github.com/beego/beego","ecosystem":"Go","purl":"pkg:golang/github.com/beego/beego"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"1.12.11"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-28r6-jm5h-mrgg/GHSA-28r6-jm5h-mrgg.json"}}],"schema_version":"1.9.0"}