LOW
GHSA-h9wq-xcqx-mqxm
Vendure Cross Site Request Forgery vulnerability impacting all API requests
Quick fix
GHSA-h9wq-xcqx-mqxm — @vendure/core: upgrade to the fixed version with the command below.
npm install @vendure/core@2.0.3Details
### Impact Vendure is an e-commerce GraphQL framework with a number of APIs and different levels of authorization. By default the Cookie settings are insecure, having the SameSite setting as false which results in not having one (originates from the cookie-session npm package’s default settings).
### Patches In progress
### Workarounds Manually set the `authOptions.cookieOptions.sameSite` configuration option to `'strict'`, `'lax'` or `true`.
### References _Are there any links users can visit to find out more?_
Are you affected?
Enter the version of the package you're using.