Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/effectindex/tripreporter
  4. ›
  5. CVE-2023-31123

CVE-2023-31123: Improper Authentication

May 8, 2023 (updated May 15, 2023)

effectindex/tripreporter is a community-powered, universal platform for submitting and analyzing trip reports. Prior to commit bd80ba833b9023d39ca22e29874296c8729dd53b, any user with an account on an instance of effectindex/tripreporter, e.g. subjective.report, may be affected by an improper password verification vulnerability. The vulnerability allows any user with a password matching the password requirements to log in as any user. This allows access to accounts / data loss of the user. This issue is patched in commit bd80ba833b9023d39ca22e29874296c8729dd53b. No action necessary for users of subjective.report, and anyone running their own instance should update to this commit or newer as soon as possible. As a workaround, someone running their own instance may apply the patch manually.

References

  • github.com/effectindex/tripreporter/commit/bd80ba833b9023d39ca22e29874296c8729dd53b
  • github.com/effectindex/tripreporter/security/advisories/GHSA-356r-rwp8-h6m6
  • nvd.nist.gov/vuln/detail/CVE-2023-31123

Code Behaviors & Features

Detect and mitigate CVE-2023-31123 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 2023-04-30

Fixed versions

  • v2023-04-30

Solution

Upgrade to version 2023-04-30 or above.

Impact 9.1 CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Learn more about CVSS

Weakness

  • CWE-287: Improper Authentication

Source file

go/github.com/effectindex/tripreporter/CVE-2023-31123.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:15:55 +0000.