mwdb-core is vulnerable to Missing Authorization
70
High Risk
The Remote Instances proxy API in mwdb-core forwards requests to a configured remote MWDB instance without verifying that the caller is authenticated. Requests that reach the proxy endpoints are executed against the remote instance using the identity and permissions of the configured API key. Before the fix, unauthenticated callers can relay arbitrary requests through the proxy and perform actions on the remote instance. The fix adds an authorization requirement to the remote proxy endpoints and enforces capability checks on remote upload operations.
You are affected if you are using a version that falls within the vulnerable range and you have configured Remote Instances on your MWDB Core instance.
mwdb-core is vulnerable to Missing Authorization in versions 2.2.0 - 2.18.0.
Upgrade the mwdb-core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant