CVE-2023-35167

    Dashboard / Vulnerabilities / CVE-2023-35167

    CVE-2023-35167

    Published: 23 Jun 2023Last Modified: 12 Aug 2026

    Summary: When setting EntityOptions.apiPrefilter to a function, the filter is not applied to API requests for a resource by Id

    Details: Remult is a CRUD framework for full-stack TypeScript. If you used the apiPrefilter option of the `@Entity` decorator, by setting it to a function that returns a filter that prevents unauthorized access to data, an attacker who knows the `id` of an entity instance is not authorized to access, can gain read, update and delete access to it. The issue is fixed in version 0.20.6. As a workaround, set the `apiPrefilter` option to a filter object instead of a function.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Affected versions

    v0.20.5
    v0.20.4
    v0.20.3
    v0.20.2
    v0.20.1
    v0.20.1-exp.1
    v0.20.1-exp.0
    v0.20.0
    v0.20.0-exp.20
    v0.20.0-exp.19
    v0.20.0-exp.18
    v0.20.0-exp.17
    v0.20.0-exp.16
    v0.20.0-exp.15
    v0.20.0-exp.14
    v0.20.0-exp.13
    v0.20.0-exp.12
    v0.20.0-exp.11
    v0.20.0-exp.10
    v0.20.0-exp.9
    v0.20.0-exp.8
    v0.20.0-exp.7
    v0.20.0-exp.6
    v0.20.0-exp.5
    v0.20.0-exp.4
    v0.20.0-exp.3
    v0.20.0-exp.2
    v0.20.0-exp.1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2023-35167 | CVE-DB