Vulnerabilities/

Leaking sensitive user information still possible by filtering on private with prefix fields (GHSA-9xg4-3qfm-9w8f)

Severity:
High

Description

Still able to leak private fields if using the t(number) prefix

Recommendation

Update the @strapi/database package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@strapi/database
Anything's wrong? Let us know Last updated on November 04, 2023

This issue is available in SmartScanner Professional

See Pricing