« Volver al listado

CVE-2023-46942

Estado: ModificadaAlta (7.5)—

La falta de autenticación en el paquete @evershop/evershop de NPM antes de la versión 1.0.0-rc.8 permite a atacantes remotos obtener información confidencial a través de una autorización inadecuada en los endpoints GraphQL.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-46942",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-46942",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-05-09T23:31:14.005291Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2024-01-13T02:15:07.153",
  "references": [
    {
      "url": "https://advisory.checkmarx.net/advisory/CVE-2023-46942",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://devhub.checkmarx.com/cve-details/CVE-2023-46942/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://devhub.checkmarx.com/cve-details/Cx00cea2d5-d2c5/",
      "tags": [
        "Not Applicable"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://advisory.checkmarx.net/advisory/CVE-2023-46942",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://devhub.checkmarx.com/cve-details/CVE-2023-46942/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://devhub.checkmarx.com/cve-details/Cx00cea2d5-d2c5/",
      "tags": [
        "Not Applicable"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Lack of authentication in NPM's package @evershop/evershop before version 1.0.0-rc.8, allows remote attackers to obtain sensitive information via improper authorization in GraphQL endpoints."
    },
    {
      "lang": "es",
      "value": "La falta de autenticación en el paquete @evershop/evershop de NPM antes de la versión 1.0.0-rc.8 permite a atacantes remotos obtener información confidencial a través de una autorización inadecuada en los endpoints GraphQL."
    }
  ],
  "lastModified": "2026-06-17T06:31:51.817",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:evershop:evershop:1.0.0:beta:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "72063F43-AC4F-4522-98FE-D19F226F447E"
            },
            {
              "criteria": "cpe:2.3:a:evershop:evershop:1.0.0:beta1:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "76A46DCC-B506-4BB0-BBEE-7888E295CCF4"
            },
            {
              "criteria": "cpe:2.3:a:evershop:evershop:1.0.0:beta2:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BE498E9E-EE3C-44DC-9606-CEBE443FA9C7"
            },
            {
              "criteria": "cpe:2.3:a:evershop:evershop:1.0.0:beta3:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BA6D2B18-4489-4622-B9E0-612C64528652"
            },
            {
              "criteria": "cpe:2.3:a:evershop:evershop:1.0.0:beta4:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "692BA821-AF49-4317-BD88-9AC950EEFE2D"
            },
            {
              "criteria": "cpe:2.3:a:evershop:evershop:1.0.0:beta5:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D4892919-5F76-4913-948C-9001B4A4CBBF"
            },
            {
              "criteria": "cpe:2.3:a:evershop:evershop:1.0.0:rc1:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1B1AB70B-5FE5-422F-AB27-AF8B6F6CCAFC"
            },
            {
              "criteria": "cpe:2.3:a:evershop:evershop:1.0.0:rc2:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D76D041A-031D-4117-A582-71EBBD8D57E0"
            },
            {
              "criteria": "cpe:2.3:a:evershop:evershop:1.0.0:rc3:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D0E794D9-AC2D-4A42-A55B-70C41F5515B1"
            },
            {
              "criteria": "cpe:2.3:a:evershop:evershop:1.0.0:rc5:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4A8E6238-4AE3-46F0-8C7D-14266B554A59"
            },
            {
              "criteria": "cpe:2.3:a:evershop:evershop:1.0.0:rc6:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "08D9F6D3-DA15-4A6C-B72E-6E05414615FD"
            },
            {
              "criteria": "cpe:2.3:a:evershop:evershop:1.0.0:rc7:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F9EDF547-27B6-4025-BEA9-7EF9E9A4F3BA"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}