GHSA-j8v8-g9cx-5qf4: @better-auth/scim: Account/provider takeover via missing owner binding on non-org SCIM providers
@better-auth/scim does not bind non-organization SCIM providers to their creator in the default configuration. Any authenticated user can manage another user’s non-org provider, including reading its metadata, listing connections, regenerating its SCIM bearer token, and deleting the connection. Regenerating the token rotates it: the legitimate token stops working and the attacker holds a valid one.
References
Code Behaviors & Features
Detect and mitigate GHSA-j8v8-g9cx-5qf4 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →