Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. @apollosproject/data-connector-rock
  4. ›
  5. CVE-2021-32691

CVE-2021-32691: Improper Authentication

June 16, 2021 (updated July 2, 2022)

Apollos Apps is an open source platform for launching church-related apps. In Apollos Apps, new user registrations are able to access anyone’s account by only knowing their basic profile information (name, birthday, gender, etc). This includes all app functionality within the app, as well as any authenticated links to Rock-based webpages (such as giving and events). There is a patch As a workaround, one can patch one’s server by overriding the create data source method on the People class.

References

  • nvd.nist.gov/vuln/detail/CVE-2021-32691

Code Behaviors & Features

Detect and mitigate CVE-2021-32691 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 2.20.0

Fixed versions

  • 2.20.0

Solution

Upgrade to version 2.20.0 or above.

Impact 9.8 CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-287: Improper Authentication

Source file

npm/@apollosproject/data-connector-rock/CVE-2021-32691.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:15:45 +0000.