11.5.3
11 years ago
18 days ago
Known vulnerabilities in the atlassian-connect-express package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
atlassian-connect-express is a Library for building Atlassian Add-ons on top of Express Affected versions of this package are vulnerable to Incorrect Authorization due to improper validation of JWT types used during the authentication process. An attacker can bypass authentication restrictions by sending authenticated re-installation events using context JWTs instead of the required server-to-server JWTs. How to fix Incorrect Authorization? Upgrade | >=3.0.2 <6.6.0 |