Incorrect Authorization in serverless-offline
Critical severity
GitHub Reviewed
Published
Sep 1, 2021
to the GitHub Advisory Database
•
Updated Sep 5, 2023
Description
Published by the National Vulnerability Database
Aug 10, 2021
Reviewed
Aug 30, 2021
Published to the GitHub Advisory Database
Sep 1, 2021
Last updated
Sep 5, 2023
Serverless Offline 8.0.0 returns a 403 HTTP status code for a route that has a trailing
/
character, which might cause a developer to implement incorrect access control, because the actual behavior within the Amazon AWS environment is a 200 HTTP status code (i.e., possibly greater than expected permissions).References