In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Information Exposure vulnerabilities in an interactive lesson.
Start learningUpgrade @redwoodjs/api to version 2.2.5, 3.3.1 or higher.
@redwoodjs/api is a
Affected versions of this package are vulnerable to Information Exposure such that a reset token for any user can be obtained given knowledge of their username or email via the forgot-password API. With the leaked reset token, a malicious user could request to reset a user's password, changing their credentials and gaining access to their account.