{"id":"GHSA-4g53-vp7q-gfjv","aliases":[],"url":"https://o3.security/vulnerability/GHSA-4g53-vp7q-gfjv","summary":"constructEvent does not verify header","details":"### Impact\nAnyone verifying a Stripe webhook request via this library's `constructEvent` function.\n\n### Patches\nUpgrade to 1.1.4. \n\n### Workarounds\nUse `await verifyHeader(...)` directly instead of `constructEvent`.\n\n### References\nhttps://github.com/worker-tools/stripe-webhook/issues/1\n","published":"2021-05-28T19:18:28Z","modified":"2021-05-27T22:24:49Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"@worker-tools/stripe-webhook","fixedVersion":"1.1.4"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/worker-tools/stripe-webhook/security/advisories/GHSA-4g53-vp7q-gfjv"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2021-05-27T22:24:49Z"}}