Intel

AIKIDO-2024-10496

supabase is vulnerable to Weak Password Requirements

Weak Password Requirements Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Nov 29, 2024

20

Low Risk

This Affects:

jssupabase
0.0.1 - 1.225.3
Fixed in 1.226.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package do not support specifying minimum password length or enforcing password complexity requirements in the TOML configuration. This lack of restrictions allows users to create weak, easily guessable passwords, increasing the risk of account compromise through brute force or dictionary attacks.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

supabase is vulnerable to Weak Password Requirements in versions 0.0.1 - 1.225.3.

How to fix this

Upgrade the supabase library to the patch version.