2.20.2-3
2 years ago
13 days ago
Known vulnerabilities in the @whyour/qinglong package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
@whyour/qinglong is a Timed task management platform supporting Python3, JavaScript, Shell, Typescript Affected versions of this package are vulnerable to Improper Handling of Case Sensitivity.
due to the case-sensitive string matching in authentication middleware. A remote attacker can bypasses the auth check by sending How to fix Improper Handling of Case Sensitivity? Upgrade | <2.20.2-0 |
@whyour/qinglong is a Timed task management platform supporting Python3, JavaScript, Shell, Typescript Affected versions of this package are vulnerable to Remote Code Execution (RCE) via the application's Express.js middleware that allows to rewrite How to fix Remote Code Execution (RCE)? Upgrade | <2.20.2-0 |