Skip to content

Unsecured /v1/users endpoint #7

@ghost

Description

Not sure if you are aware, but users can be queried including their hashed passwords and private information by visiting the following REST endpoint:
https://immoperium.herokuapp.com/v1/users

You might consider securing it via API Keys or other means, limiting the shown information or remove it entirely.

Hope you'll find these information useful c:

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions