@cedarjs/auth-dbauth-setup is vulnerable to Predictable Exact Value from Previous Values
51
Medium Risk
Affected versions of this package are vulnerable to a Predictable User ID Sequence vulnerability due to the use of sequential integers for user IDs, which makes it easy to guess valid IDs and estimate system user count. An attacker can exploit this by brute-forcing or iterating through possible IDs to enumerate user accounts, potentially leading to unauthorized access or data exposure. While UUIDs are now the default for dbAuth to mitigate this, developers can still switch to auto-incrementing integers, maintaining the risk if not properly configured.
You are affected if you are using a version that falls within the vulnerable range.
@cedarjs/auth-dbauth-setup is vulnerable to Predictable Exact Value from Previous Values in versions 0.1.0 - 2.3.1.
Upgrade the @cedarjs/auth-dbauth-setup library to a patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant