datasette-indieauth
Datasette authentication using IndieAuth and RelMeAuth
Activity
- Latest release
- 3y ago
- Total releases
- 11
- Cadence
- ~daily
- Last 12 months
- 0
Details
- License
- Apache-2.0
- First release
- Nov 15, 2020
Releases
| Version | Released | |
|---|---|---|
1.2.2
patch
| ||
1.2.1
patch
| ||
1.2
minor
| ||
1.1
minor
| ||
1.0
major
1 CVE
GHSA-mjcr-rqjg-rhg3
Nov 24, 2020
Implementation trusts the "me" field returned by the authorization server without verifying it
Critical
ImpactA malicious user can sign in as a user with any IndieAuth identifier. This is because the implementation does not verify that the final PatchesVersion 1.1 fixes this issue. WorkaroundsThere is no workaround. Upgrade to 1.1 immediately. References
For more informationIf you have any questions or comments about this advisory:
Affected versions
1.0
Fixed in
1.1
References Updated Mar 21, 2022 · Source: OSV.dev | ||
0.3.2
patch
| ||
0.3.1
patch
| ||
0.3
initial
| ||
0.3a0
pre
| ||
0.2a0
pre
| ||
0.1a0
pre
|