Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2021-4236
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Panic or authentication bypass in github.com/ecnepsnai/web
Source: NVD (National Vulnerability Database)
Vulnerability Description
Web Sockets do not execute any AuthenticateMethod methods which may be set, leading to a nil pointer dereference if the returned UserData pointer is assumed to be non-nil, or authentication bypass. This issue only affects WebSockets with an AuthenticateMethod hook. Request handlers that do not explicitly use WebSockets are not vulnerable.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
ecnepsnai web 代码问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Web是Ian Spence个人开发者的一个 Golang 的 HTTP 服务器。用于复杂的 web 应用程序。 ecnepsnai web存在安全漏洞,该漏洞源于Web Sockets 不执行任何可能设置的 AuthenticateMethod 方法,如果返回的 UserData 指针被假定为非 nil 或身份验证绕过,则会导致 nil 指针取消引用。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
github.com/ecnepsnai/webgithub.com/ecnepsnai/web 1.4.0 ~ 1.5.2 -
II. Public POCs for CVE-2021-4236
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2021-4236
Please Login to view more intelligence information
V. Comments for CVE-2021-4236

No comments yet


Leave a comment