Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-ggpm-9qfx-mhwg: EverShop vulnerable to improper authorization in GraphQL endpoints

Lack of authentication in NPM’s package @evershop/evershop before version 1.0.0-rc.9, allows remote attackers to obtain sensitive information via improper authorization in GraphQL endpoints.

ghsa
#nodejs#git#auth

EverShop vulnerable to improper authorization in GraphQL endpoints

Moderate severity GitHub Reviewed Published Jan 13, 2024 to the GitHub Advisory Database • Updated Jan 16, 2024

ghsa: Latest News

GHSA-g85v-wf27-67xc: Harden-Runner has a command injection weaknesses in `setup.ts` and `arc-runner.ts`