GHSA-v66p-w7qx-wv98

Suggest an improvement
Source
https://github.com/advisories/GHSA-v66p-w7qx-wv98
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-v66p-w7qx-wv98/GHSA-v66p-w7qx-wv98.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-v66p-w7qx-wv98
Published
2020-09-04T17:29:34Z
Modified
2020-08-31T18:59:44Z
Summary
Authentication Bypass in express-laravel-passport
Details

All versions of express-laravel-passport are vulnerable to an Authentication Bypass. The package fails to properly validate JWTs, allowing attackers to send HTTP requests impersonating other users.

Recommendation

Upgrade to version 2.0.5 or later.

Database specific
{
    "cwe_ids":  [
        "CWE-287"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2020-08-31T18:59:44Z",
    "nvd_published_at":  null,
    "severity":  "CRITICAL"
}
References

Affected packages

npm / express-laravel-passport

Package

Name
express-laravel-passport
View open source insights on deps.dev
Purl
pkg:npm/express-laravel-passport

Affected ranges

Type
SEMVER
Events
Introduced
0.0.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-v66p-w7qx-wv98/GHSA-v66p-w7qx-wv98.json"