CRITICAL9.8
GHSA-mvmv-rq2j-97p2
Etherpad Lite Access Restriction Bypass
Quick fix
GHSA-mvmv-rq2j-97p2 — ep_etherpad-lite: upgrade to the fixed version with the command below.
npm install ep_etherpad-lite@1.6.3Details
`node/hooks/express/apicalls.js` in Etherpad Lite before v1.6.3 mishandles JSONP, which allows remote attackers to bypass intended access restrictions.
Are you affected?
Enter the version of the package you're using.