{ "schema_version": "1.4.0", "id": "GHSA-q7pj-xc3r-rm4w", "modified": "2022-05-24T17:37:10Z", "published": "2022-05-24T17:37:10Z", "aliases": [ "CVE-2020-35666" ], "details": "Steedos Platform through 1.21.24 allows NoSQL injection because the /api/collection/findone implementation in server/packages/steedos_base.js mishandles req.body validation, as demonstrated by MongoDB operator attacks such as an X-User-Id[$ne]=1 value.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-35666" }, { "type": "WEB", "url": "https://github.com/steedos/steedos-platform/issues/1245" } ], "database_specific": { "cwe_ids": [ "CWE-89" ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2020-12-23T20:15:00Z" } }