296,137
Total vulnerabilities in the database
Vendure is an e-commerce GraphQL framework with a number of APIs and different levels of authorization. By default the Cookie settings are insecure, having the SameSite setting as false which results in not having one (originates from the cookie-session npm package’s default settings).
In progress
Manually set the authOptions.cookieOptions.sameSite
configuration option to 'strict'
, 'lax'
or true
.
Are there any links users can visit to find out more?