Skip to content

CSRF impacting all API requests

Low
michaelbromley published GHSA-h9wq-xcqx-mqxm Jul 11, 2023

Package

npm @vendure/core (npm)

Affected versions

< 2.0.3

Patched versions

2.0.3

Description

Impact

Vendure is an e-commerce GraphQL framework with a number of APIs and different levels of
authorization. By default the Cookie settings are insecure, having the SameSite setting as false
which results in not having one (originates from the cookie-session npm package’s default
settings).

Patches

In progress

Workarounds

Manually set the authOptions.cookieOptions.sameSite configuration option to 'strict', 'lax' or true.

References

Are there any links users can visit to find out more?

Severity

Low

CVE ID

No known CVE

Weaknesses

No CWEs

Credits