astro is vulnerable to Authentication Bypass Using an Alternate Path or Channel
80
High Risk
Affected versions of this package are vulnerable to authentication bypass through double-URL encoded paths. An attacker could use multi-level URL encoding (e.g. /%2561dmin) to access routes that should be behind authentication. The patch fixes this by decoding pathnames and rejecting requests that contain leftover percent-encoded sequences after decoding.
You are affected if you are using a version that falls within the vulnerable range.
astro is vulnerable to Authentication Bypass Using an Alternate Path or Channel in versions 3.5.6 - 5.16.2.
Upgrade the astro library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant