Sensitive Data Exposure in loopback
Low severity
GitHub Reviewed
Published
Sep 2, 2020
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Package
Affected versions
<= 2.41.0
>= 3.0.0, <= 3.25.0
Patched versions
2.42.0
3.26.0
Description
Reviewed
Aug 31, 2020
Published to the GitHub Advisory Database
Sep 2, 2020
Last updated
Jan 9, 2023
Versions of
loopbackprior to 3.26.0 (3.x) and 2.42.0 (2.x) are vulnerable to Sensitive Data Exposure. Invalid API requests to the login endpoint may return information about the first user in the database. This can be used alongside other attacks for credential theft.Recommendation
If you're using
loopback3.x upgrade to version 3.26.0 or later.If you're using
loopback2.x upgrade to version 2.42.0 or later.References