GHSA-r578-pj6f-r4ff

    Dashboard / Vulnerabilities / GHSA-r578-pj6f-r4ff

    GHSA-r578-pj6f-r4ff

    Published: 21 Jun 2021Last Modified: 8 Jul 2026

    Summary: Auto-merging Person Records Compromised

    Details: ### Impact New user registrations are able to access anyone's account by only knowing their basic profile information (name, birthday, gender, etc). This includes all app functionality within the app, as well as any authenticated links to Rock-based webpages (such as giving and events). ### Patches We have released a security patch on v2.20.0. The solution was to create a duplicate person and then patch the new person with their profile details. ### Workarounds If you do not wish to upgrade your app to the new version, you can patch your server by overriding the `create` data source method on the `People` class. ```js create = async (profile) => { const rockUpdateFields = this.mapApollosFieldsToRock(profile); // auto-merge functionality is compromised // we are creating a new user and patching them with profile details const id = await this.post('/People', { Gender: 0, // required by Rock. Listed first so it can be overridden. IsSystem: false, // required by rock }); await this.patch(`/People/${id}`, { ...rockUpdateFields, }); return id; }; ``` ### For more information If you have any questions or comments about this advisory: * Email us at [[email protected]](mailto:[email protected])

    Affected packages

    Package

    Name: @apollosproject/data-connector-rock

    Purl: pkg:npm/%40apollosproject/data-connector-rock

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -2.20.0

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-r578-pj6f-r4ff | CVE-DB