Intel

AIKIDO-2024-10082

@algolia/autocomplete-plugin-algolia-insights is vulnerable to Improper Authentication

Improper Authentication Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published May 3, 2024

25

Low Risk

This Affects:

JS@algolia/autocomplete-plugin-algolia-insights
1.0.0 - 1.15.0
Fixed in 1.15.1
Are you affected? Scan for Free

TL;DR

Affected versions of the @algolia/autocomplete-plugin-algolia-insights library are vulnerable to improper authentication. In some cases, user tokens can be accidentally updated when authenticated user tokens are already set, potentially allowing unauthorized access.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@algolia/autocomplete-plugin-algolia-insights is vulnerable to Improper Authentication in versions 1.0.0 - 1.15.0.

How to fix this

Upgrade the @algolia/autocomplete-plugin-algolia-insights library to the patch version.