Vulnerabilities > CVE-2021-38384 - Improper Handling of Exceptional Conditions vulnerability in Serverless Offline Project Serverless Offline 8.0.0
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
Serverless Offline 8.0.0 returns a 403 HTTP status code for a route that has a trailing / character, which might cause a developer to implement incorrect access control, because the actual behavior within the Amazon AWS environment is a 200 HTTP status code (i.e., possibly greater than expected permissions).
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |