{"id":"GO-2022-0920","title":"Incorrect Authorization in ORY Oathkeeper in github.com/ory/oathkeeper","summary":"Incorrect Authorization in ORY Oathkeeper in github.com/ory/oathkeeper","severity":"none","vendor":"ory","product":"github.com/ory/oathkeeper","ecosystem":"go","affected":["github.com/ory/oathkeeper >= 0.38.0-beta.2, < 0.38.12-beta.1"],"patched":["github.com/ory/oathkeeper 0.38.12-beta.1"],"published":"2024-08-21","updated":"2026-07-08","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GO-2022-0920","references":[{"url":"https://github.com/advisories/GHSA-vfvf-6gx5-mqv6"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-32701"},{"url":"https://github.com/ory/oathkeeper/commit/1f9f625c1a49e134ae2299ee95b8cf158feec932"},{"url":"https://github.com/ory/oathkeeper/pull/424"},{"url":"https://github.com/ory/oathkeeper/security/advisories/GHSA-qvp4-rpmr-xwrr"}],"tags":["osv","go"],"ingestedAt":"2026-07-09T18:56:37.003Z","slug":"GO-2022-0920","body":"## Overview\n\nIncorrect Authorization in ORY Oathkeeper in github.com/ory/oathkeeper\n\n## Affected packages\n\n- `github.com/ory/oathkeeper >= 0.38.0-beta.2, < 0.38.12-beta.1`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `github.com/ory/oathkeeper 0.38.12-beta.1`","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}