QID 981312
QID 981312: Nodejs (npm) Security Update for serverless-offline (GHSA-h97f-5258-5593)
Serverless Offline 8.0.0 returns a 403 HTTP status code for a route that has a trailing / character, which might cause a developer to implement incorrect access control, because the actual behavior within the Amazon AWS environment is a 200 HTTP status code (i.e., possibly greater than expected permissions).
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-h97f-5258-5593 for updates pertaining to this vulnerability.
Vendor References
- GHSA-h97f-5258-5593 -
github.com/advisories/GHSA-h97f-5258-5593
CVEs related to QID 981312
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-h97f-5258-5593 | serverless-offline |
|