Description
Serverless Offline 8.0.0 returns a 403 HTTP status code for a route that has a trailing / character, which might cause a developer to implement incorrect access control, because the actual behavior within the Amazon AWS environment is a 200 HTTP status code (i.e., possibly greater than expected permissions).
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-2069 | Serverless Offline 8.0.0 returns a 403 HTTP status code for a route that has a trailing / character, which might cause a developer to implement incorrect access control, because the actual behavior within the Amazon AWS environment is a 200 HTTP status code (i.e., possibly greater than expected permissions). |
Github GHSA |
GHSA-h97f-5258-5593 | Incorrect Authorization in serverless-offline |
References
| Link | Providers |
|---|---|
| https://github.com/dherault/serverless-offline/issues/1259 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T01:37:16.558Z
Reserved: 2021-08-10T00:00:00.000Z
Link: CVE-2021-38384
No data.
Status : Modified
Published: 2021-08-10T18:15:07.513
Modified: 2024-11-21T06:16:57.640
Link: CVE-2021-38384
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA