ethyca-fides is vulnerable to Authentication Bypass Using an Alternate Path or Channel
60
Medium Risk
Affected versions of this package skip the identity-verification check on privacy requests classified as duplicates, so administrators can approve them even when the requester was never verified. An unverified requester could trigger personal-data actions through a crafted duplicate request.
You are affected if you are using a version that falls within the vulnerable range.
ethyca-fides is vulnerable to Authentication Bypass Using an Alternate Path or Channel in versions 2.75.0 - 2.83.1.
Upgrade the ethyca-fides library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant