Description
Lack of authentication in NPM’s package @evershop/evershop before version 1.0.0-rc.9, allows remote attackers to obtain sensitive information via improper authorization in GraphQL endpoints.
Recommendation
Update the @evershop/evershop package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.0.0-rc.9
- Patched version(s): 1.0.0-rc.9
References
- GHSA-ggpm-9qfx-mhwg
- advisory.checkmarx.net
- devhub.checkmarx.com
- CVE-2023-46942
- CWE-285
- CWE-287
- CAPEC-310
- OWASP 2021-A1
- OWASP 2021-A6
- OWASP 2021-A7
Related Issues
- Cross-site Scripting in evershop - CVE-2023-46499
- Code execution in evershop - CVE-2023-46498
- Directory Traversal in evershop - CVE-2023-46497
- EverShop at risk to unauthorized access via weak HMAC secret - CVE-2023-46943
You might also like:
- Tags:
- npm
- @evershop/evershop
Anything's wrong? Let us know Last updated on July 26, 2024


