Snyk has a proof-of-concept or detailed explanation of how to exploit this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Authorization Bypass Through User-Controlled Key vulnerabilities in an interactive lesson.
Start learningUpgrade @withstudiocms/effect to version 0.4.1 or higher.
@withstudiocms/effect is an Effect-TS Utilities for Astro
Affected versions of this package are vulnerable to Authorization Bypass Through User-Controlled Key in the getUsers process. An attacker can access sensitive owner account information, such as IDs, usernames, display names, and email addresses, by supplying a crafted rank query parameter while authenticated as an admin. This allows bypassing intended authorization boundaries and retrieving privileged user data.