Sensitive Data Exposure in loopback
Low severity
GitHub Reviewed
Published
Sep 2, 2020
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Package
Affected versions
<= 2.41.0
>= 3.0.0, <= 3.25.0
Patched versions
2.42.0
3.26.0
Description
Reviewed
Aug 31, 2020
Published to the GitHub Advisory Database
Sep 2, 2020
Last updated
Jan 9, 2023
Versions of
loopback
prior to 3.26.0 (3.x) and 2.42.0 (2.x) are vulnerable to Sensitive Data Exposure. Invalid API requests to the login endpoint may return information about the first user in the database. This can be used alongside other attacks for credential theft.Recommendation
If you're using
loopback
3.x upgrade to version 3.26.0 or later.If you're using
loopback
2.x upgrade to version 2.42.0 or later.References