VDB
Sign up
HIGH

GHSA-8wgc-jjvv-cv6v

Improper Authorization in loopback

Quick fix

GHSA-8wgc-jjvv-cv6v — loopback: upgrade to the fixed version with the command below.

npm install loopback@2.40.0

Details

Vulnerable versions of `loopback` may allow attackers to create Authentication Tokens on behalf of other users due to Improper Authorization. If the AccessToken model is publicly exposed, an attacker can create Authorization Tokens for any user as long as they know the target's `userId`. This will allow the attacker to access the user's data and their privileges.

## Recommendation

For loopback 2.x, upgrade to version 2.40.0 or later For loopback 3.x, upgrade to version 3.22.0 or later

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/loopback
Introduced in: 0Fixed in: 2.40.0
Fixnpm install loopback@2.40.0
npm/loopback
Introduced in: 3.0.0Fixed in: 3.22.0
Fixnpm install loopback@3.22.0

References