Import tokens valid for one account may be used for any other account.
Validation of Import token bindings incorrectly warns on mismatches, rather than rejecting the Goken. This permits a token for one account to be used for any other account.
{ "review_status": "REVIEWED", "url": "https://pkg.go.dev/vuln/GO-2022-0386" }