CVE-2021-38384: Incorrect Authorization
(updated )
Serverless Offline returns a HTTP status code for a route that has a trailing /
character, which might cause a developer to implement incorrect access control, because the actual behavior within the Amazon AWS environment is a HTTP status code (i.e., possibly greater than expected permissions).
References
Detect and mitigate CVE-2021-38384 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →