Skip to content

Fix NoSQL injection in allocations-dao (CWE-943) - #464

Open
it24103309 wants to merge 18 commits into
OWASP:masterfrom
Ravindu-orzo:IT24103309
Open

it24103309 wants to merge 18 commits into
OWASP:masterfrom
Ravindu-orzo:IT24103309

Conversation

@it24103309

Copy link
Copy Markdown

Fixes NoSQL injection (CWE-943) in getByUserIdAndThreshold() in app/data/allocations-dao.js.

The threshold input was concatenated into a MongoDB $where expression, allowing JS injection. It is now parsed with parseInt and range-checked (0-99); invalid input throws an error. Also added *.bak to .gitignore

Ravindu-orzo and others added 18 commits August 23, 2026 05:31
Updated Node.js version and repository URL in setup instructions.
Clarified setup instructions for NodeGoat, emphasizing the use of IntelliJ Ultimate and SSH key setup for GitHub.
Updated instructions for running NodeGoat and MongoDB.
Updated comments for clarity regarding the scanning processes and their implications.
Updated GitHub Actions workflow to use newer versions of actions and added Semgrep installation step.
Updated Node.js version in the workflow configuration.
If this causes issues then revert to the commit before this
Updated DAST scanning step to use Docker Compose for starting the NodeGoat application and added waiting logic.
Added permissions for DAST scan to write results to GitHub issues.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants