Vulnerabilities/

botframework-connector vulnerable to Improper Authentication

Severity:
Medium

Description

A maliciously crafted claim may be incorrectly authenticated by the bot. Impacts bots that are not configured to be used as a Skill. This vulnerability requires an attacker to have internal knowledge of the bot.

Recommendation

Update the botframework-connector package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
botframework-connector
Anything's wrong? Let us know Last updated on January 11, 2024

This issue is available in SmartScanner Professional

See Pricing