GHSA-h97f-5258-5593
Dashboard / Vulnerabilities / GHSA-h97f-5258-5593
Summary: Incorrect Authorization in serverless-offline
Details: Serverless Offline 8.0.0 returns a 403 HTTP status code for a route that has a trailing `/` character, which might cause a developer to implement incorrect access control, because the actual behavior within the Amazon AWS environment is a 200 HTTP status code (i.e., possibly greater than expected permissions).
References: https://nvd.nist.gov/vuln/detail/CVE-2021-38384, https://github.com/dherault/serverless-offline/issues/1259, https://github.com/dherault/serverless-offline
Affected packages
Package
Name: serverless-offline
Purl: pkg:npm/serverless-offline
Affected ranges
Type: SEMVER
Events:
Introduced- 0
Fixed -None
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
