@curveball/a12n-server/.../a12n-server@0.18.1 vulnerabilities

A ready-to-launch User and Authentication system for those that don't want to build it

  • latest version

    0.27.5

  • latest non vulnerable version

  • first published

    3 years ago

  • latest version published

    2 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the @curveball/a12n-server package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Access Restriction Bypass

    @curveball/a12n-server is a This package aims to provide a simple authentication system.

    Affected versions of this package are vulnerable to Access Restriction Bypass via improper privilege verification in a new form which allows unprivileged logged-in users to edit other users information.

    How to fix Access Restriction Bypass?

    Upgrade @curveball/a12n-server to version 0.18.2 or higher.

    >=0.18.0 <0.18.2