CVE-2021-32691: Improper Authentication
(updated )
Apollos Apps is an open source platform for launching church-related apps. In Apollos Apps, new user registrations are able to access anyone’s account by only knowing their basic profile information (name, birthday, gender, etc). This includes all app functionality within the app, as well as any authenticated links to Rock-based webpages (such as giving and events). There is a patch As a workaround, one can patch one’s server by overriding the create
data source method on the People
class.
References
Detect and mitigate CVE-2021-32691 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →