3.0.0
14 years ago
10 years ago
Known vulnerabilities in the paypal-ipn package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for freeVulnerability | Vulnerable Version |
---|---|
paypal-ipn uses the "With a bit of time, an attacker could craft a request using the simulator that would fool any application which does not explicitly check for test_ipn in production." [1] Source: Node Security Project How to fix Validation Bypass? Upgrade to version 3.0.0 or greater. | <3.0.0 |