Snyk has reported that there have been attempts or successful attacks targeting this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade @whyour/qinglong to version 2.20.2-0 or higher.
@whyour/qinglong is a Timed task management platform supporting Python3, JavaScript, Shell, Typescript
Affected versions of this package are vulnerable to Improper Handling of Case Sensitivity.
due to the case-sensitive string matching in authentication middleware. A remote attacker can bypasses the auth check by sending /aPi/system/command-run request instead of /api/system/command-run allowing them to obtain administrative access without authorisation.