Логотип exploitDog
bind:CVE-2016-10533
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2016-10533

Количество 2

Количество 2

nvd логотип

CVE-2016-10533

больше 7 лет назад

express-restify-mongoose is a module to easily create a flexible REST interface for mongoose models. express-restify-mongoose 2.4.2 and earlier and 3.0.X through 3.0.1 allows a malicious user to send a request for `GET /User?distinct=password` and get all the passwords for all the users in the database, despite the field being set to private. This can be used for other private data if the malicious user knew what was set as private for specific routes.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-cgjx-mwpx-47jv

больше 7 лет назад

Private Data Disclosure in express-restify-mongoose

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2016-10533

express-restify-mongoose is a module to easily create a flexible REST interface for mongoose models. express-restify-mongoose 2.4.2 and earlier and 3.0.X through 3.0.1 allows a malicious user to send a request for `GET /User?distinct=password` and get all the passwords for all the users in the database, despite the field being set to private. This can be used for other private data if the malicious user knew what was set as private for specific routes.

CVSS3: 8.8
0%
Низкий
больше 7 лет назад
github логотип
GHSA-cgjx-mwpx-47jv

Private Data Disclosure in express-restify-mongoose

0%
Низкий
больше 7 лет назад

Уязвимостей на страницу