← Back

Express Restify Mongoose

express-restify-mongoose

Vendor: Express Restify Mongoose Project • 1 CVE

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Express Restify Mongoose Project
1Express Restify Mongoose
Nov 21, 2024
May 31, 2018
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
express-restify-mongoose is a module to easily create a flexible REST interface for mongoose models. express-restify-mongoose 2.4.2 and earlier and 3.0.X through 3.0.1 allows a malicious user to send a request for `GET /...Show more
express-restify-mongoose is a module to easily create a flexible REST interface for mongoose models. express-restify-mongoose 2.4.2 and earlier and 3.0.X through 3.0.1 allows a malicious user to send a request for `GET /User?distinct=password` and get all the passwords for all the users in the database, despite the field being set to private. This can be used for other private data if the malicious user knew what was set as private for specific routes.Show less