CVE-2013-7379

Tomato <0.0.6 - Auth Bypass

Title source: llm

Description

The admin API in the tomato module before 0.0.6 for Node.js does not properly check the access key when it is set to a string, which allows remote attackers to bypass authentication via a string in the access-key header that partially matches config.master.api.access_key.

Scores

EPSS 0.0036
EPSS Percentile 57.8%

Classification

CWE
CWE-287
Status draft

Affected Products (2)

ucdok/tomato < 0.0.5
npm/tomato < 0.0.6npm

Timeline

Published May 16, 2014
Tracked Since Feb 18, 2026