Количество 2
Количество 2
CVE-2016-10533
express-restify-mongoose is a module to easily create a flexible REST interface for mongoose models. express-restify-mongoose 2.4.2 and earlier and 3.0.X through 3.0.1 allows a malicious user to send a request for `GET /User?distinct=password` and get all the passwords for all the users in the database, despite the field being set to private. This can be used for other private data if the malicious user knew what was set as private for specific routes.
GHSA-cgjx-mwpx-47jv
Private Data Disclosure in express-restify-mongoose
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2016-10533 express-restify-mongoose is a module to easily create a flexible REST interface for mongoose models. express-restify-mongoose 2.4.2 and earlier and 3.0.X through 3.0.1 allows a malicious user to send a request for `GET /User?distinct=password` and get all the passwords for all the users in the database, despite the field being set to private. This can be used for other private data if the malicious user knew what was set as private for specific routes. | CVSS3: 8.8 | 0% Низкий | больше 7 лет назад | |
GHSA-cgjx-mwpx-47jv Private Data Disclosure in express-restify-mongoose | 0% Низкий | больше 7 лет назад |
Уязвимостей на страницу