{"id":"GHSA-xf64-2f9p-6pqq","aliases":[],"url":"https://o3.security/vulnerability/GHSA-xf64-2f9p-6pqq","summary":"Information Exposure in type-graphql","details":"Versions of `type-graphql` prior to 0.17.6 are vulnerable to Information Exposure. The package leaks the resolver source code in an error message. It is possible to force this error when no subscription topics are provided in the request.\n\n\n## Recommendation\n\nUpgrade to version 0.17.6 or later.","published":"2020-09-04T17:24:08Z","modified":"2020-08-31T18:59:32Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"type-graphql","fixedVersion":"0.17.6"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/MichalLytek/type-graphql/issues/489"},{"type":"WEB","url":"https://www.npmjs.com/advisories/1444"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2020-08-31T18:59:32Z"}}