tsaekaoOrg / nodegoat

Apache License 2.0
0 stars 0 forks source link

Authorization Bypass Through User-Controlled Key [VID:639:app/data/contributions-dao.js:57] #10

Open veracode-workflow-app[bot] opened 5 months ago

veracode-workflow-app[bot] commented 5 months ago

https://github.com/tsaekaoOrg/nodegoat/blob/94315c5421ccfc8451501ccc4c679d6e99004688/app/data/contributions-dao.js#L52-L62

Filename: app/data/contributions-dao.js

Line: 57

CWE: 639 (Authorization Bypass Through User-Controlled Key)

The property named findOne contains untrusted data, and (due to its name) may contain internal authorization data. Ensure that nothing in this application relies on this value to be a trusted indicator of security privilege or identity. References: CWE/nDon't know how to fix this? Don't know why this was reported?
Get Assistance from Veracode