Vulnerability GO-2024-2936
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
2 years ago
July 01, 2024 at 07:59 PM UTC
PocketBase performs password auth and OAuth2 unverified email linking in github.com/pocketbase/pocketbase
v0.1.0 - v0.22.14-rc
v0.1.0 - v0.22.14-rc
Summary
PocketBase performs password auth and OAuth2 unverified email linking in github.com/pocketbase/pocketbase
Details
PocketBase performs password auth and OAuth2 unverified email linking in github.com/pocketbase/pocketbase
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
20 days ago
Pocketbase: Unhandled panic in worker goroutines
v0.1.0 - v0.22.47 and v0.23.0 - v0.39.6 GHSA-84vh-m24q-wjjx
v0.1.0 - v0.22.47 and v0.23.0 - v0.39.6 GHSA-84vh-m24q-wjjx
Unknown
2 months ago
PocketBase: Account pre-hijacking via OAuth2 autolinking upgrade in github.com/pocketbase/pocketbase
v0.1.0 - v0.22.41 GO-2026-5548
v0.1.0 - v0.22.41 GO-2026-5548
Medium Risk
5 months ago
PocketBase vulnerable to account pre-hijacking via OAuth2 unverfied->verified autolinking upgrade
v0.1.0 - v0.22.41 and v0.30.0 - v0.37.3 GHSA-pq7p-mc74-g65w
v0.1.0 - v0.22.41 and v0.30.0 - v0.37.3 GHSA-pq7p-mc74-g65w
Medium Risk
2 years ago
PocketBase performs password auth and OAuth2 unverified email linking
v0.1.0 - v0.22.14-rc GHSA-m93w-4fxv-r35v
v0.1.0 - v0.22.14-rc GHSA-m93w-4fxv-r35v
Impacted packages
Timeline
Published
2 years ago
July 01, 2024 at 07:59 PM UTC
Last Modified
2 years ago
July 01, 2024 at 08:29 PM UTC