In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Incorrect Authorization vulnerabilities in an interactive lesson.
Start learningUpgrade stigmem-node to version 0.9.0a12 or higher.
stigmem-node is a Stigmem reference node — single-host production implementation
Affected versions of this package are vulnerable to Incorrect Authorization in the run_decay_sweep process. An attacker can access or modify data belonging to other tenants by initiating a decay sweep with a write credential for one tenant, which acts on all tenants' facts due to missing tenant scoping. This is only exploitable if the deployment is running the opt-in stigmem-plugin-multi-tenant configuration.