| id: GO-2023-1955 |
| modules: |
| - module: github.com/dapr/dapr |
| versions: |
| - fixed: 1.10.9 |
| - introduced: 1.11.0 |
| - fixed: 1.11.2 |
| vulnerable_at: 1.11.2-rc.3 |
| summary: Dapr API token authentication bypass in HTTP endpoints in github.com/dapr/dapr |
| cves: |
| - CVE-2023-37918 |
| ghsas: |
| - GHSA-59m6-82qm-vqgj |
| references: |
| - advisory: https://github.com/dapr/dapr/security/advisories/GHSA-59m6-82qm-vqgj |
| - advisory: https://nvd.nist.gov/vuln/detail/CVE-2023-37918 |
| - fix: https://github.com/dapr/dapr/commit/83ca1abb11ffe34211db55dcd36d96b94252827a |
| - fix: https://github.com/dapr/dapr/commit/99d6799c97b79397443c8c96737c9b893126a1ae |
| - web: https://docs.dapr.io/operations/security/api-token |
| source: |
| id: GHSA-59m6-82qm-vqgj |
| created: 2024-08-20T11:54:37.185639-04:00 |
| review_status: UNREVIEWED |
| unexcluded: EFFECTIVELY_PRIVATE |