If the file authentication backend is being used, the ewatch option is set to true, the refresh interval is configured to a non-disabled value, and an administrator changes a user's groups, then that user may be able to access resources that their previous groups had access to.
{ "review_status": "REVIEWED", "url": "https://pkg.go.dev/vuln/GO-2024-2744" }