mage-ai is vulnerable to Initialization of a Resource with an Insecure Default
61
Medium Risk
Affected versions of this package ship with an insecure default for the REQUIRE_USER_AUTHENTICATION setting. An attacker can initiate this remotely; while exploitation is reported to be non-trivial (higher complexity) and considered difficult in practice, a public disclosure exists and may enable real-world abuse.
You are affected if you are using a version that falls within the vulnerable range.
mage-ai is vulnerable to Initialization of a Resource with an Insecure Default in versions 0.7.90 - 0.9.77.
Upgrade the mage-ai library to the patch version or set REQUIRE_USER_AUTHENTICATION to true.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant