QID 982743
QID 982743: Nodejs (npm) Security Update for @curveball/a12n-server (GHSA-8hw9-22v6-9jr9)
Security update has been released for @curveball/a12n-server to fix the vulnerability.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Everyone who is running a12n-server.
A new HAL-Form was added to allow editing users. This feature should only have been accessible to admins. Unfortunately, privileges were incorrectly checked allowing any logged in user to make this change.
Solution
Patched in v0.18.2
Vendor References
- GHSA-8hw9-22v6-9jr9 -
github.com/advisories/GHSA-8hw9-22v6-9jr9
CVEs related to QID 982743
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-8hw9-22v6-9jr9 | @curveball/a12n-server |
|