VDB
Sign up
HIGH7.0

GHSA-vhh6-v828-x62f

SAP Approuter has an Information Disclosure vulnerability

Quick fix

GHSA-vhh6-v828-x62f — @sap/approuter: upgrade to the fixed version with the command below.

npm install @sap/approuter@23.0.0

Details

SAP Approuter does not sufficiently validate certain token content under specific configurations. An unauthenticated attacker could send a specially crafted token to cause sensitive credential material to be sent to an attacker-controlled destination. The attack complexity is high due to non-default preconditions required in the target environment. This results in a high impact on confidentiality and a low impact on integrity and availability.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@sap/approuter
Introduced in: 0Fixed in: 23.0.0
Fixnpm install @sap/approuter@23.0.0

References