VDB
Sign up
LOW

GHSA-h9wq-xcqx-mqxm

Vendure Cross Site Request Forgery vulnerability impacting all API requests

Quick fix

GHSA-h9wq-xcqx-mqxm — @vendure/core: upgrade to the fixed version with the command below.

npm install @vendure/core@2.0.3

Details

### Impact Vendure is an e-commerce GraphQL framework with a number of APIs and different levels of authorization. By default the Cookie settings are insecure, having the SameSite setting as false which results in not having one (originates from the cookie-session npm package’s default settings).

### Patches In progress

### Workarounds Manually set the `authOptions.cookieOptions.sameSite` configuration option to `'strict'`, `'lax'` or `true`.

### References _Are there any links users can visit to find out more?_

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@vendure/core
Introduced in: 0Fixed in: 2.0.3
Fixnpm install @vendure/core@2.0.3

References