kinto@0.2 vulnerabilities

Kinto Web Service - Store, Sync, Share, and Self-Host.

  • latest version

    20.6.1

  • latest non vulnerable version

  • first published

    10 years ago

  • latest version published

    3 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the kinto package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Race Condition

    Affected versions of this package are vulnerable to Race Condition during the replacement of permissions of an object in a PostgreSQL backend. This problem arises when two separate queries, one deleting old permissions and another inserting new ones, are executed simultaneously.

    How to fix Race Condition?

    Upgrade kinto to version 6.1.0 or higher.

    [,6.1.0)
    • M
    Race Condition

    Affected versions of this package are vulnerable to Race Condition during concurrent delete/update operations.

    How to fix Race Condition?

    Upgrade kinto to version 6.1.0 or higher.

    [,6.1.0)
    • M
    Race Condition

    Affected versions of this package are vulnerable to Race Condition in permission.postgresql:replace_object_permissions.

    How to fix Race Condition?

    Upgrade kinto to version 7.0.0 or higher.

    [,7.0.0)
    • M
    Insufficient Password Verification

    kinto is a minimalist JSON storage service with synchronisation and sharing abilities.

    Affected versions of this package are vulnerable to Insufficient Password Verification. The account plugin had a security flaw where the password wasn't verified during the session duration.

    How to fix Insufficient Password Verification?

    Upgrade kinto to version 8.2.3 or higher.

    [,8.2.3)