Vulnerabilities/

Redwood is vulnerable to account takeover via dbAuth "forgot-password

Severity:
High

Description

This is an API vulnerability in Redwood’s [dbAuth], specifically the dbAuth forgot password feature:

Recommendation

Update the @redwoodjs/api package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@redwoodjs/api
Anything's wrong? Let us know Last updated on January 07, 2023

This issue is available in SmartScanner Professional

See Pricing