CVE-2023-46942: High severity evershop vulnerability
Lack of authentication in NPM's package @evershop/evershop before version 1.0.0-rc.9, allows remote attackers to obtain sensitive information via improper authorization in GraphQL endpoints.
Other sources
Lack of authentication in NPM's package @evershop/evershop before version 1.0.0-rc.8, allows remote attackers to obtain sensitive information via improper authorization in GraphQL endpoints.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-46942?
CVE-2023-46942 has been classified with a high severity due to its potential for exposing sensitive information through improper authorization.
How do I fix CVE-2023-46942?
To mitigate CVE-2023-46942, update the package @evershop/evershop to version 1.0.0-rc.9 or later.
Which versions of @evershop/evershop are affected by CVE-2023-46942?
CVE-2023-46942 affects all versions of @evershop/evershop prior to 1.0.0-rc.9.
How does CVE-2023-46942 impact security?
CVE-2023-46942 allows remote attackers to access sensitive information, compromising the security of applications using the affected package.
What are the common exploit scenarios for CVE-2023-46942?
Common exploit scenarios for CVE-2023-46942 include unauthorized access to GraphQL endpoints by remote attackers.