Medium severity5.0NVD Advisory· Published Dec 20, 2022· Updated Jun 17, 2026
CVE-2022-39304
CVE-2022-39304
Description
ghinstallation provides transport, which implements http.RoundTripper to provide authentication as an installation for GitHub Apps. In ghinstallation version 1, when the request to refresh an installation token failed, the HTTP request and response would be returned for debugging. The request contained the bearer JWT for the App, and was returned back to clients. This token is short lived (10 minute maximum). This issue has been patched and is available in version 2.0.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/bradleyfalzon/ghinstallationGo | < 2.0.0 | 2.0.0 |
Affected products
3- cpe:2.3:a:ghinstallation_project:ghinstallation:*:*:*:*:*:*:*:*Range: <2.0.0
- Range: < 2.0.0
Patches
Vulnerability mechanics
References
8- github.com/bradleyfalzon/ghinstallation/commit/d24f14f8be70d94129d76026e8b0f4f9170c8c3envdPatchThird Party AdvisoryWEB
- github.com/bradleyfalzon/ghinstallation/security/advisories/GHSA-h4q8-96p6-jcgrnvdPatchThird Party AdvisoryWEB
- github.com/bradleyfalzon/ghinstallation/blob/24e56b3fb7669f209134a01eff731d7e2ef72a5c/transport.gonvdExploitThird Party AdvisoryWEB
- docs.github.com/en/developers/apps/building-github-apps/authenticating-with-github-appsnvdTechnical DescriptionThird Party AdvisoryWEB
- github.com/advisories/GHSA-h4q8-96p6-jcgrghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-39304ghsaADVISORY
- securitylab.github.com/advisories/GHSL-2022-061_ghinstallationghsaADVISORY
- pkg.go.dev/vuln/GO-2022-1178ghsaWEB
News mentions
0No linked articles in our index yet.