remult@0.20.2 vulnerabilities

A CRUD framework for full-stack TypeScript

Direct Vulnerabilities

Known vulnerabilities in the remult package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Improper Authorization

remult is an A CRUD framework for full-stack TypeScript

Affected versions of this package are vulnerable to Improper Authorization such that when setting EntityOptions.apiPrefilter to a function, the filter is not applied to API requests for a resource by Id. As a result, an attacker can gain read, update and delete access to an instance.

Note:

An attacker will need to prepare the attack by gaining access to an id of an entity instance he is not authorized to access.

How to fix Improper Authorization?

Upgrade remult to version 0.20.6 or higher.

<0.20.6