Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h9wq-xcqx-mqxm

Опубликовано: 11 июл. 2023
Источник: github
Github: Прошло ревью

Описание

Vendure Cross Site Request Forgery vulnerability impacting all API requests

Impact

Vendure is an e-commerce GraphQL framework with a number of APIs and different levels of authorization. By default the Cookie settings are insecure, having the SameSite setting as false which results in not having one (originates from the cookie-session npm package’s default settings).

Patches

In progress

Workarounds

Manually set the authOptions.cookieOptions.sameSite configuration option to 'strict', 'lax' or true.

References

Are there any links users can visit to find out more?

Пакеты

Наименование

@vendure/core

npm
Затронутые версииВерсия исправления

< 2.0.3

2.0.3