Vulnerability Report: GO-2024-3016
- CVE-2024-40464, GHSA-r6qh-j42j-pw64
- Affects: github.com/beego/beego/v2
- Published: Aug 19, 2024
Beego privilege escalation vulnerability via sendMail in github.com/beego/beego/v2
For detailed information about this vulnerability, visit https://github.com/advisories/GHSA-r6qh-j42j-pw64.
Affected Packages
-
PathGo VersionsSymbols
-
before v2.2.1
49 affected symbols
- AccessLog
- Alert
- Async
- BeeLogger.Alert
- BeeLogger.Async
- BeeLogger.Close
- BeeLogger.Critical
- BeeLogger.Debug
- BeeLogger.DelLogger
- BeeLogger.Emergency
- BeeLogger.Error
- BeeLogger.Flush
- BeeLogger.Info
- BeeLogger.Informational
- BeeLogger.Notice
- BeeLogger.Reset
- BeeLogger.SetLogger
- BeeLogger.Trace
- BeeLogger.Warn
- BeeLogger.Warning
- BeeLogger.Write
- ColorByMethod
- ColorByStatus
- Critical
- Debug
- Emergency
- Error
- GetLogger
- Info
- Informational
- JLWriter.Format
- JLWriter.Init
- JLWriter.WriteMsg
- LogMsg.OldStyleFormat
- NewLogger
- Notice
- PatternLogFormatter.Format
- PatternLogFormatter.ToString
- Reset
- SLACKWriter.Format
- SLACKWriter.Init
- SLACKWriter.WriteMsg
- SMTPWriter.Format
- SMTPWriter.Init
- SMTPWriter.WriteMsg
- SetLogger
- Trace
- Warn
- Warning
Aliases
References
- https://github.com/advisories/GHSA-r6qh-j42j-pw64
- https://gist.github.com/nyxfqq/b53b0148b9aa040de63f58a68fd11445
- https://github.com/beego/beego/commit/8f89e12e6cafb106d5c201dbc3b2a338bfde74e2
- https://github.com/beego/beego/security/advisories/GHSA-6g9p-wv47-4fxq
- https://vuln.go.dev/ID/GO-2024-3016.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.