CVE-2016-10533
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
express-restify-mongoose is a module to easily create a flexible REST interface for mongoose models. express-restify-mongoose 2.4.2 and earlier and 3.0.X through 3.0.1 allows a malicious user to send a request for `GET /User?distinct=password` and get all the passwords for all the users in the database, despite the field being set to private. This can be used for other private data if the malicious user knew what was set as private for specific routes.
express-restify-mongoose es un modulo para crear fácilmente una interfaz REST flexible para modelos mongoose. express-restify-mongoose en versiones 2.4.2 y anteriores y versiones 3.0.X hasta la 3.0.1 permite que un usuario malicioso envíe una petición para "GET /User?distinct=password" y obtenga todas las contraseñas de todos los usuarios de la base de datos, aunque el campo esté marcado como privado. Esto puede emplearse para otro tipo de datos privados si el usuario malicioso sabe qué se marca como privado en rutas específicas.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-10-29 CVE Reserved
- 2018-05-31 CVE Published
- 2023-10-22 EPSS Updated
- 2024-09-17 CVE Updated
- 2024-09-17 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://github.com/florianholzapfel/express-restify-mongoose/issues/252 | Issue Tracking |
URL | Date | SRC |
---|---|---|
https://nodesecurity.io/advisories/92 | 2024-09-17 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Express-restify-mongoose Project Search vendor "Express-restify-mongoose Project" | Express-restify-mongoose Search vendor "Express-restify-mongoose Project" for product "Express-restify-mongoose" | <= 2.4.2 Search vendor "Express-restify-mongoose Project" for product "Express-restify-mongoose" and version " <= 2.4.2" | node.js |
Affected
| ||||||
Express-restify-mongoose Project Search vendor "Express-restify-mongoose Project" | Express-restify-mongoose Search vendor "Express-restify-mongoose Project" for product "Express-restify-mongoose" | >= 3.0.0 <= 3.0.1 Search vendor "Express-restify-mongoose Project" for product "Express-restify-mongoose" and version " >= 3.0.0 <= 3.0.1" | node.js |
Affected
|