remult@0.4.4 vulnerabilities

A CRUD framework for full-stack TypeScript

  • latest version

    0.27.24

  • latest non vulnerable version

  • first published

    3 years ago

  • latest version published

    1 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the remult package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Improper Authorization

    remult is an A CRUD framework for full-stack TypeScript

    Affected versions of this package are vulnerable to Improper Authorization such that when setting EntityOptions.apiPrefilter to a function, the filter is not applied to API requests for a resource by Id. As a result, an attacker can gain read, update and delete access to an instance.

    Note:

    An attacker will need to prepare the attack by gaining access to an id of an entity instance he is not authorized to access.

    How to fix Improper Authorization?

    Upgrade remult to version 0.20.6 or higher.

    <0.20.6