If
sqlpage/sqlpage.json configuration file (not in an environment variable)then an attacker could retrieve the database connection information from SQLPage and use it to connect to your database directly.
Upgrade to v0.11.1 as soon as possible.
If you cannot upgrade immediately:
{
"cwe_ids": [
"CWE-200"
],
"github_reviewed": true,
"github_reviewed_at": "2023-09-21T17:10:06Z",
"nvd_published_at": "2023-09-18T22:15:47Z",
"severity": "CRITICAL"
}