HIGH7.5
GHSA-ggpm-9qfx-mhwg
EverShop vulnerable to improper authorization in GraphQL endpoints
Quick fix
GHSA-ggpm-9qfx-mhwg — @evershop/evershop: upgrade to the fixed version with the command below.
npm install @evershop/evershop@1.0.0-rc.9Details
Lack of authentication in NPM's package @evershop/evershop before version 1.0.0-rc.9, allows remote attackers to obtain sensitive information via improper authorization in GraphQL endpoints.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/@evershop/evershop
Introduced in:
0Fixed in: 1.0.0-rc.9Fix
npm install @evershop/evershop@1.0.0-rc.9References
- https://nvd.nist.gov/vuln/detail/CVE-2023-46942[ADVISORY]
- https://github.com/evershopcommerce/evershop/commit/6e16f046e0b95efa16431a5ea41c22215273e9dd[WEB]
- https://advisory.checkmarx.net/advisory/CVE-2023-46942[WEB]
- https://devhub.checkmarx.com/cve-details/CVE-2023-46942[WEB]
- https://devhub.checkmarx.com/cve-details/Cx00cea2d5-d2c5[WEB]
- https://github.com/evershopcommerce/evershop[PACKAGE]