CyberRota Analysis
AI-GeneratedSuperTokens Core versions 6.0.0 to 11.4.0 exhibit a vulnerability due to inadequate tenant separation, enabling authenticated users from one tenant to access the sessions, data, and endpoints of another tenant. This flaw poses a risk of unauthorized data exposure and potential data manipulation across tenants. Organizations utilizing SuperTokens for multi-tenant applications should prioritize addressing this vulnerability to safeguard sensitive information and maintain tenant isolation.
Original NVD Description
A lack of tenant separation in SuperTokens Inc. SuperTokens Core v6.0.0 to v11.4.0 allows an authenticated party in one tenant to access sessions, data, and endpoints of another tenant.