Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-29hq-23m2-2j47
  • npm/@sync-in/server
Sync-in Server has Username/Login Enumeration via Timing Side-Channel on POST /api/auth/login (incomplete fix of the prior timing-attack advisory) 22 Sep
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-jx63-h26r-8cph
  • npm/@sync-in/server
Sync-in Server has a ReDoS via Unsanitized Regex in Sync Diff `pathFilters` 22 Sep
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-92cr-jxw4-5wjg
  • npm/@sync-in/server
Sync-in Server has a complete 2FA Bypass via `POST /api/auth/token` 22 Sep
  • Fix available
  • Severity - 8.1 (High)
GHSA-274f-6w77-8qm9
  • npm/@sync-in/server
@sync-in/server vulnerable to TOTP Brute-Force via `POST /api/app/sync/register` 22 Sep
  • Fix available
  • Severity - 6.8 (Medium)
GHSA-q4x5-8cj6-52wg
  • npm/@sync-in/server
Sync-in Server: SSRF protection bypass via IPv4-mapped IPv6 addresses in regExpPrivateIP 05 Jun
  • Fix available
  • Severity - 7.7 (High)
GHSA-43fj-qp3h-hrh5
  • npm/@sync-in/server
Sync-in Server has Username Enumeration via Timing Attack 15 Apr
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-9jmq-xgjm-p8c2
  • npm/@sync-in/server
Sync-in Server has a stored cross-site scripting (XSS) vulnerability 20 Feb
  • Fix available
  • Severity - 5.1 (Medium)