Description
Server JWT signing secret was included in static assets and served to clients.
This ALLOWS Flood’s builtin authentication to be bypassed.
Recommendation
Update the flood package to the latest compatible version. Followings are version details:
- Affected version(s): >= 2.0.0, < 3.0.0
- Patched version(s): 3.0.0
References
Related Issues
- static-server Path Traversal vulnerability - CVE-2023-26152
- google-translate-api-browser Server-Side Request Forgery (SSRF) Vulnerability - CVE-2023-48711
- Vite XSS vulnerability in `server.transformIndexHtml` via URL payload - CVE-2023-49293
- lobe-chat `/api/proxy` endpoint Server-Side Request Forgery vulnerability - CVE-2024-32964
You might also like:
- Tags:
- npm
- flood
Anything's wrong? Let us know Last updated on January 06, 2023


