← Back

CVE-2022-23773

nvd nist
Published: Feb 11, 2022Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

cmd/go in Go before 1.16.14 and 1.17.x before 1.17.7 can misinterpret branch names that falsely appear to be version tags. This can lead to incorrect access control if an actor is supposed to be able to create branches but not tags.

Affected (6)

1 product
Go
4 products
Beegfs Csi Driver
Cloud Insights Telegraf Agent
Kubernetes Monitoring Operator
Storagegrid
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Golang
Before 1.16.14
From 1.17.0 to 1.17.7
Configuration B
4 vulnerable
Vulnerable SoftwareAffected Versions
All versions
All versions
All versions
All versions

References (8)

Source: cve@mitre.org
Release NotesVendor Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.