
@curveball/a12n-server
Releases72
Frequency3 weeks 2 days
Last Release
A ready-to-launch User and Authentication system for those that don't want to build it
CVE History
| CVE | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|
| 8.1 HIGH | 4 MEDIUM | ||
a12n-server is an npm package which aims to provide a simple authentication system. A new HAL-Form was added to allow editing users in version 0.18.0. This feature should only have been accessible to admins. Unfortunately, privileges were incorrectly checked allowing any logged in user to make this change. Patched in v0.18.2. | |||