漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Hoppscotch: Insecure Default Configuration Allows Public Exposure of Private Collection Data via Mock Server
Vulnerability Description
Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, mock server creation in mock-server.service.ts does not persist the isPublic input field while schema.prisma defaults isPublic to true, causing mock servers linked to private collections to be publicly accessible without authentication and potentially expose sensitive API data. This issue is fixed in version 2026.6.0.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
信息暴露
Vulnerability Title
Hoppscotch 信息泄露漏洞
Vulnerability Description
Hoppscotch是Hoppscotch组织开源的一个Api开发生态系统。 Hoppscotch 2026.6.0之前版本存在安全漏洞,该漏洞源于mock-server.service.ts中的mock server创建未持久化isPublic输入字段,而schema.prisma将isPublic默认为true,导致与私有集合关联的mock server可被公开访问,从而可能泄露敏感API数据。
CVSS Information
N/A
Vulnerability Type
N/A