Skip to content

Fix NoSQL injection and secure environment secrets - #462

Closed
Sasmitha444 wants to merge 1 commit into
OWASP:masterfrom
Sasmitha444:master
Closed

Sasmitha444 wants to merge 1 commit into
OWASP:masterfrom
Sasmitha444:master

Conversation

@Sasmitha444

Copy link
Copy Markdown

Fix NoSQL Injection and Secure Environment Secrets

Changes Made

  • Fixed the NoSQL injection vulnerability by validating and parsing the user-supplied threshold value before using it in the MongoDB query.
  • Added input range validation to allow only valid threshold values.
  • Moved sensitive configuration values to environment variables instead of hard-coding them.
  • Added .env.example to document the required environment variables without exposing real secrets.
  • Updated Docker and application configuration to support environment-based secrets management.

Security Impact

These changes prevent malicious input from being directly incorporated into the MongoDB query and reduce the risk of sensitive configuration values being exposed in the source code.

@Sasmitha444
Sasmitha444 deleted the branch OWASP:master September 30, 2026 11:13
@Sasmitha444
Sasmitha444 deleted the master branch September 30, 2026 11:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant