---
title: "CVE-2020-36627\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2020-36627?format=md
keywords: index, follow
---

# CVE-2020-36627

Publication date 25 December 2022

Last updated 26 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**5.5 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2020-36627?format=md#impact-score)

Toggle side navigation

## Description

A vulnerability was found in Macaron i18n. It has been declared as
problematic. Affected by this vulnerability is an unknown functionality of
the file i18n.go. The manipulation leads to open redirect. The attack can
be launched remotely. Upgrading to version 0.5.0 is able to address this
issue. The name of the patch is 329b0c4844cc16a5a253c011b55180598e707735.
It is recommended to upgrade the affected component. The identifier
VDB-216745 was assigned to this vulnerability.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2020-36627?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| golang-github-go-macaron-i18n | 26.04 LTS resolute | Not in release |
| 25.10 questing | Not in release |
| 25.04 plucky | Not in release |
| 24.10 oracular | Not in release |
| 24.04 LTS noble | Not in release |
| 23.10 mantic | Not in release |
| 23.04 lunar | Ignored end of life, was needed |
| 22.10 kinetic | Ignored end of life, was needed |
| 22.04 LTS jammy | Vulnerable |
| 20.04 LTS focal | Vulnerable |
| 18.04 LTS bionic | Vulnerable |
| 16.04 LTS xenial | Not in release |
| 14.04 LTS trusty | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2020-36627?format=md#patch-details)

## Notes

---

### [eslerm](https://launchpad.net/~eslerm)

CVE possibly assigned based on commit message

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| golang-github-go-macaron-i18n | * Upstream:   [329b0c4](https://github.com/go-macaron/i18n/commit/329b0c4844cc16a5a253c011b55180598e707735) |

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

5.5 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | Low |
  | User interaction | Required |
  | Scope | Unchanged |
  | Confidentiality impact | Low |
  | Integrity impact | Low |
  | Availability impact | Low |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 5.5 · Medium |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-36627)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2020-36627)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2020-36627)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2020-36627)

### Other references

* <https://github.com/go-macaron/i18n/releases/tag/v0.5.0>
* <https://www.cve.org/CVERecord?id=CVE-2020-36627>
