@signalk/server-admin-ui is vulnerable to Improper Authentication
80
High Risk
Affected versions allow authentication bypasses where WebSocket clients can override their authenticated identity by providing a per-message token. Additionally, if OIDC is disabled or misconfigured, insufficient validation allows unauthorized access to OIDC-protected routes.
You are affected if you are using a version that falls within the vulnerable range.
@signalk/server-admin-ui is vulnerable to Improper Authentication in versions 0.0.1 - 2.25.0.
Upgrade the @signalk/server-admin-ui library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant