Description
Server JWT signing secret was included in static assets and served to clients.
This ALLOWS Flood’s builtin authentication to be bypassed.
Recommendation
Update the flood
package to the latest compatible version. Followings are version details:
- Affected version(s): >= 2.0.0, < 3.0.0
- Patched version(s): 3.0.0
References
Related Issues
- Trix allows Cross-site Scripting via `javascript:` url in a link - CVE-2025-21610
- CommonRegexJS Regular Expression Denial of Service vulnerability - CVE-2020-26305
- Undici vulnerable to data leak when using response.arrayBuffer() - CVE-2024-38372
- Default swagger-ui configuration exposes all files in the module - CVE-2024-22207
- Tags:
- npm
- flood
Anything's wrong? Let us know Last updated on January 06, 2023