HIGH7.0
GHSA-vhh6-v828-x62f
SAP Approuter has an Information Disclosure vulnerability
Quick fix
GHSA-vhh6-v828-x62f — @sap/approuter: upgrade to the fixed version with the command below.
npm install @sap/approuter@23.0.0Details
SAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated attacker could send a specially crafted token to cause sensitive credential material to be sent to an attacker-controlled destination. The attack complexity is high due to non-default preconditions required in the target environment. This results in a high impact on confidentiality and a low impact on integrity and availability.
Are you affected?
Enter the version of the package you're using.