CVE-2013-7379

ucdok/tomato < 0.0.5 and npm/tomato < 0.0.6 - Improper Authentication via Partial Access Key Match

Title source: llm
STIX 2.1

Description

The admin API in the tomato module before 0.0.6 for Node.js does not properly check the access key when it is set to a string, which allows remote attackers to bypass authentication via a string in the access-key header that partially matches config.master.api.access_key.

References (4)

Core 4

Scores

EPSS 0.0246
EPSS Percentile 82.5%

Details

CWE
CWE-287
Status published
Products (2)
npm/tomato 0 - 0.0.6npm
ucdok/tomato < 0.0.5
Published May 16, 2014
Tracked Since Feb 18, 2026