VDB
Sign up
HIGH

GHSA-7rhv-xm4q-wh42

Erxes Incorrect Access Control vulnerability

Quick fix

GHSA-7rhv-xm4q-wh42 — erxes: upgrade to the fixed version with the command below.

npm install erxes@1.6.1

Details

Erxes <1.6.1 is vulnerable to Incorrect Access Control. An attacker can bypass authentication by providing a "User" HTTP header that contains any user, allowing them to talk to any GraphQL endpoint.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/erxes
Introduced in: 0Fixed in: 1.6.1
Fixnpm install erxes@1.6.1

References