PT-2022-3324 · Unknown+3 · Go-Restful+3

Published

2022-06-06

·

Updated

2026-01-30

·

CVE-2022-1996

CVSS v2.0

9.4

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions go-restful versions prior to v3.8.0
Description The issue is related to an authorization bypass through a user-controlled key. This could allow a remote attacker to elevate their privileges. The vulnerability is also related to CORS filters that use an AllowedDomains configuration parameter, which can match domains outside the specified set, permitting an attacker to avoid the CORS policy. The AllowedDomains configuration parameter is applied as regular expression matches, which can lead to unintended domain matches.
Recommendations For go-restful versions prior to v3.8.0, update to version v3.8.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the AllowedDomains configuration parameter to minimize the risk of exploitation. Avoid using the AllowedDomains parameter with values that can be matched as regular expressions to unintended domains until the issue is resolved.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-41344
BDU:2022-04072
CLEANSTART-2026-HV28992
CLEANSTART-2026-YS66739
CVE-2022-1996
GHSA-R48Q-9G5R-8Q2H
GO-2022-0619
OPENSUSE-SU-2022:10081-1
OPENSUSE-SU-2022:10094-1
OPENSUSE-SU-2022_3321-1
OPENSUSE-SU-2022_3333-1
OPENSUSE-SU-2022_3334-1
OPENSUSE-SU-2022_3335-1
OPENSUSE-SU-2022_3666-1
OPENSUSE-SU-2022_4606-1
OPENSUSE-SU-2023_4727-1
OPENSUSE-SU-2024:12205-1
OPENSUSE-SU-2024:12252-1
OPENSUSE-SU-2024:14081-1
OPENSUSE-SU-2024_3221-1
OPENSUSE-SU-2024_4329-1
OPENSUSE-SU-2025:15779-1
RHSA-2022:6042
RHSA-2023:3229
RHSA-2023:3557
SUSE-SU-2022:3321-1
SUSE-SU-2022:3333-1
SUSE-SU-2022:3334-1
SUSE-SU-2022:3335-1
SUSE-SU-2022:3666-1
SUSE-SU-2022:4606-1
SUSE-SU-2022_3334-1
SUSE-SU-2022_3335-1
SUSE-SU-2022_3666-1
SUSE-SU-2023:4727-1
SUSE-SU-2023_4727-1
SUSE-SU-2024:0799-1
SUSE-SU-2024:3221-1
SUSE-SU-2024:4329-1
SUSE-SU-2024_0799-1
SUSE-SU-2024_3221-1
SUSE-SU-2024_4329-1
SUSE-SU-2025:20091-1

Affected Products

Astra Linux
Debian
Suse
Go-Restful