Improper Authorization Affecting googleapis package, versions >=36.0.0 <39.1.0
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JS-GOOGLEAPIS-460104
- published 21 Aug 2019
- disclosed 28 Mar 2019
- credit Garret Meier
How to fix?
Upgrade googleapis
to version 39.1.0 or higher.
Overview
googleapis is a Google's officially supported Node.js client library for accessing Google APIs.
Affected versions of this package are vulnerable to Improper Authorization. Setting credentials to one client may apply to all clients which may cause requests to be sent with the incorrect credentials.
References
CVSS Scores
version 3.1