GHSA-hx78-272p-mqqh

Suggest an improvement
Source
https://github.com/advisories/GHSA-hx78-272p-mqqh
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-hx78-272p-mqqh/GHSA-hx78-272p-mqqh.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-hx78-272p-mqqh
Published
2020-09-03T19:21:11Z
Modified
2020-08-31T18:47:59Z
Summary
Authorization Bypass in graphql-shield
Details

Versions of graphql-shield prior to 6.0.6 are vulnerable to an Authorization Bypass. The rule caching option no_cache relies on keys generated by cryptographically insecure functions, which may cause rules to be incorrectly cached. This allows attackers to access information they should not have access to in case of a key collision.

Recommendation

Upgrade to version 6.0.6 or later.

Database specific
{
    "cwe_ids":  [
        "CWE-285"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2020-08-31T18:47:59Z",
    "nvd_published_at":  null,
    "severity":  "LOW"
}
References

Affected packages

npm / graphql-shield

Package

Name
graphql-shield
View open source insights on deps.dev
Purl
pkg:npm/graphql-shield

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
6.0.6

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-hx78-272p-mqqh/GHSA-hx78-272p-mqqh.json"