{"id":"GHSA-hx78-272p-mqqh","aliases":[],"url":"https://o3.security/vulnerability/GHSA-hx78-272p-mqqh","summary":"Authorization Bypass in graphql-shield","details":"Versions of `graphql-shield` prior to 6.0.6 are vulnerable to an Authorization Bypass. The rule caching option `no_cache` relies on keys generated by cryptographically insecure functions, which may cause rules to be incorrectly cached. This allows attackers to access information they should not have access to in case of a key collision.\n\n\n## Recommendation\n\nUpgrade to version 6.0.6 or later.","published":"2020-09-03T19:21:11Z","modified":"2020-08-31T18:47:59Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"graphql-shield","fixedVersion":"6.0.6"}],"fix":null,"references":[{"type":"WEB","url":"https://www.npmjs.com/advisories/1121"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2020-08-31T18:47:59Z"}}