Node.js Express NODE_ENV Development Mode
The Node.js application runs in development mode, which can expose sensitive information, such as source code and secrets, depending on the application.
CVSS—
共找到 4 条公开漏洞记录
The Node.js application runs in development mode, which can expose sensitive information, such as source code and secrets, depending on the application.
Mongo-Express before 1.0.0 is susceptible to remote code execution because it uses safer-eval to validate user supplied javascript. Unfortunately safer-eval sandboxing capabilities are easily bypassed leading to remote code execution in the context of the node server.
Mongo Express was able to be access with no authentication requirements in place.
mongo-express before 0.54.0 is vulnerable to remote code execution via endpoints that uses the `toBSON` method and misuse the `vm` dependency to perform `exec` commands in a non-safe environment.