QID 996720
Date Published: 2024-01-17
QID 996720: NodeJs (Npm) Security Update for @evershop/evershop (GHSA-ggpm-9qfx-mhwg)
Lack of authentication in NPM's package @evershop/evershop before version 1.0.0-rc.9, allows remote attackers to obtain sensitive information via improper authorization in GraphQL endpoints.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-ggpm-9qfx-mhwg for updates and patch information.
Vendor References
- GHSA-ggpm-9qfx-mhwg -
github.com/advisories/GHSA-ggpm-9qfx-mhwg
CVEs related to QID 996720
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-ggpm-9qfx-mhwg | @evershop/evershop |
|