In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade github.com/forgekeep/nebula-mesh/internal/store to version 0.3.8 or higher.
Affected versions of this package are vulnerable to Insufficiently Protected Credentials due to storing session tokens in plaintext in the operator_sessions table. An attacker can gain unauthorized access to operator sessions by obtaining a copy of the database through backup, snapshot, file copy, or SQL-level disclosure.
This vulnerability can be mitigated by restricting and encrypting database backups and rotating the operator database.