← Späť na vyhľadávanie CVE

CVE-2026-71214

Popis

The Aerie/PlanDev sequencing-server-s authorization middleware (sequencing-server/src/app.ts) derives the caller-s Hasura session role via getHasuraSession, which prefers a session_variables object taken directly from the client-supplied JSON request body over the Authorization header-s JWT claims, with no verification that the request actually originated from Hasura.

CVSS 9.8EPSS 0.268%Riziko 1
Zobraziť zdroj
Zverejnené
2026-08-05 08:16:43
Posledná úprava
2026-08-10 12:17:25
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H