GHSA-hx78-272p-mqqh
UNKNOWNVersions of graphql-shield prior to 6.0.6 are vulnerable to an Authorization Bypass. The rule caching option nocache relies on keys generated by cryptographically insecure functions, which may cause rules to be incorrectly cached. This allows attackers to access information they should not have access to in case of a key collision.
- Affected
- >=0, <6.0.6
- Fixed in
- not stated
- Weakness
- CWE-285
- Published
- 2020-09-03
- Source
- osv