{"schema_version":"1.9.0","id":"CVE-2022-1996","published":"2022-06-06T00:00:00Z","modified":"2026-08-12T03:51:10.405055438Z","aliases":["GHSA-r48q-9g5r-8q2h","GO-2022-0619"],"related":["CGA-hg94-jm75-6758","SUSE-SU-2022:3321-1","SUSE-SU-2022:3333-1","SUSE-SU-2022:3334-1","SUSE-SU-2022:3335-1","SUSE-SU-2022:3666-1","SUSE-SU-2022:4606-1","SUSE-SU-2023:4727-1","SUSE-SU-2024:0799-1","SUSE-SU-2024:3221-1","SUSE-SU-2024:4329-1","SUSE-SU-2025:20091-1","SUSE-SU-2026:2643-1","openSUSE-SU-2022:10081-1","openSUSE-SU-2022:10094-1","openSUSE-SU-2024:12205-1","openSUSE-SU-2024:12252-1","openSUSE-SU-2024:14081-1","openSUSE-SU-2025:15779-1"],"summary":"Authorization Bypass Through User-Controlled Key in emicklei/go-restful","details":"Authorization Bypass Through User-Controlled Key in GitHub repository emicklei/go-restful prior to v3.8.0.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/emicklei/go-restful","events":[{"introduced":"0"},{"fixed":"ac666c045e035603f2704c98c59e979fccbfa94f"},{"introduced":"aaadc18f7fcd089ec2589db0d224ba901416392a"},{"fixed":"a2ff8b3f817635c0517a65055c36901e62e96ecb"},{"fixed":"fd3c327a379ce08c68ef18765bdc925f5d9bad10"}],"database_specific":{"cpe":"cpe:2.3:a:go-restful_project:go-restful:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.16.0"},{"introduced":"3.0.0"},{"fixed":"3.8.0"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v3.7.4","v3.7.3","v3.7.2","v3.7.1","v3.7.0","v3.6.0","v3.5.2","v3.5.1","v3.5.0","v3.4.0","v2.15.0","v3.3.3","v2.14.3","v3.3.1","v2.14.2","v2.14.1","v2.14.0","v3.3.0","v3.2.0","v2.13.0","v3.1.0","v2.12.0","v3.0.1","v2.11.2","v3.0.0","v2.11.1","v2.11.0","v2.9.6","v2.9.5","v2.9.4","v2.9.3","v2.9.2","v2.9.1","v2.9.0","v2.8.0","v2.7.1","v2.6.1","v2.6.0","v2.5.0","v2.4.0","v2.3.0","v2.2.1","2.2.0","2.1.0","2.0.0","1.0.0","v1.2","v1.1.3","v1.1.2","v1.1.1","v1.1.0","v1.0.1","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-1996.json"}}],"references":[{"type":"WEB","url":"https://huntr.dev/bounties/be837427-415c-4d8c-808b-62ce20aa84f1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/1xxx/CVE-2022-1996.json"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/575BLJ3Y2EQBRNTFR2OSQQ6L2W6UCST3/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OBDD3Q23RCGAGHIXUCWBU6N3S4RNAKXB/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RQXU752ALW53OJAF5MG3WMR5CCZVLWW6/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SO5QC2JFW2PXBWAE27OYYYL5SPFUBHTY/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W56PP46JVZEKCANBKXFKRVSBBRRMCY6V/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z55VUVGO7E5PJFXIOVAY373NZRHBNCI5/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZGQKWD6SE75PFBPFVSZYAKAVXKBZXKWS/"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZY2SLWOQR4ZURQ7UBRZ7JIX6H6F5JHJR/"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-1996"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20220923-0005/"},{"type":"FIX","url":"https://github.com/emicklei/go-restful/commit/fd3c327a379ce08c68ef18765bdc925f5d9bad10"}],"database_specific":{"cna_assigner":"@huntrdev","cwe_ids":["CWE-639"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/1xxx/CVE-2022-1996.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N"}]}