HIGH7.5
GHSA-mx8q-jqwm-85mv
NocoDB information disclosure vulnerability
Quick fix
GHSA-mx8q-jqwm-85mv — nocodb: upgrade to the fixed version with the command below.
npm install nocodb@0.91.7Details
In NocoDB prior to 0.91.7, the SMTP plugin doesn't have verification or validation. This allows attackers to make requests to internal servers and read the contents.
Are you affected?
Enter the version of the package you're using.