OSV 1.4.0 · github-reviewed · 修改于 2020-09-01 02:47
发布时间
2020-09-04 03:21
GitHub 审查时间
2020-09-01 02:47
NVD 发布时间
—
源文件
advisories/github-reviewed/2020/09/GHSA-hx78-272p-mqqh/GHSA-hx78-272p-mqqh.json
Versions of graphql-shield prior to 6.0.6 are vulnerable to an Authorization Bypass. The rule caching option no_cache relies on keys generated by cryptographically insecure functions, which may cause rules to be incorrectly cached. This allows attackers to access information they should not have access to in case of a key collision.
Upgrade to version 6.0.6 or later.