Description
Serverless Offline 8.0.0 returns a 403 HTTP status code for a route that has a trailing /
character, which might cause a developer to implement incorrect access control, because the actual behavior within the Amazon AWS environment is a 200 HTTP status code (i.e., possibly greater than expected permissions).
Recommendation
No fix is available yet. Followings are affected versions:
- <= 8.0.0
References
Related Issues
- counterpart vulnerable to prototype pollution - CVE-2025-57354
- Parse Server has an OAuth login vulnerability - CVE-2025-30168
- Use of Insufficiently Random Values in undici - CVE-2025-22150
- SummerNote Cross Site Scripting Vulnerability - CVE-2024-37629
- Tags:
- npm
- serverless-offline
Anything's wrong? Let us know Last updated on September 05, 2023