@curveball/a12n-server

@curveball/a12n-server

Releases72
Frequency3 weeks 2 days
Last Release
A ready-to-launch User and Authentication system for those that don't want to build it

CVE History

CVEPublishedCVSS v3CVSS v2
8.1 HIGH4 MEDIUM

a12n-server is an npm package which aims to provide a simple authentication system. A new HAL-Form was added to allow editing users in version 0.18.0. This feature should only have been accessible to admins. Unfortunately, privileges were incorrectly checked allowing any logged in user to make this change. Patched in v0.18.2.