GHSA-724c-6vrf-99rq

Suggest an improvement
Source
https://github.com/advisories/GHSA-724c-6vrf-99rq
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-724c-6vrf-99rq/GHSA-724c-6vrf-99rq.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-724c-6vrf-99rq
Downstream
Published
2020-09-02T21:49:48Z
Modified
2021-09-27T22:31:27Z
Summary
Sensitive Data Exposure in loopback
Details

Versions of loopback prior to 3.26.0 (3.x) and 2.42.0 (2.x) are vulnerable to Sensitive Data Exposure. Invalid API requests to the login endpoint may return information about the first user in the database. This can be used alongside other attacks for credential theft.

Recommendation

If you're using loopback 3.x upgrade to version 3.26.0 or later. If you're using loopback 2.x upgrade to version 2.42.0 or later.

Database specific
{
    "cwe_ids":  [
        "CWE-200"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2020-08-31T18:40:25Z",
    "nvd_published_at":  null,
    "severity":  "LOW"
}
References

Affected packages

npm / loopback

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.42.0

Database specific

last_known_affected_version_range
"<= 2.41.0"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-724c-6vrf-99rq/GHSA-724c-6vrf-99rq.json"

npm / loopback

Package

Affected ranges

Type
SEMVER
Events
Introduced
3.0.0
Fixed
3.26.0

Database specific

last_known_affected_version_range
"<= 3.25.0"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-724c-6vrf-99rq/GHSA-724c-6vrf-99rq.json"