Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

"NoSQL Injection - MongoDB" high alert showing in report but we are not using mongoDB #8483

Open
1 task
jitendra-90 opened this issue May 10, 2024 · 5 comments

Comments

@jitendra-90
Copy link

Describe the bug

"NoSQL Injection - MongoDB" high alert showing in report but we are not using mongoDB

Steps to reproduce the behavior

"NoSQL Injection - MongoDB" high alert showing in report but we are not using mongoDB

Expected behavior

"NoSQL Injection - MongoDB" high alert showing in report but we are not using mongoDB

Software versions

2.14.0

Screenshots

No response

Errors from the zap.log file

No response

Additional context

No response

Would you like to help fix this issue?

  • Yes
@thc202
Copy link
Member

thc202 commented May 10, 2024

Please provide more details of the alert.

@jitendra-90
Copy link
Author

jitendra-90 commented May 10, 2024

Bellow is the description of alert while we are not using MongoDb in our application
High Alert --> NoSQL Injection - MongoDB
Description --> MongoDB query injection may be possible.
Attack --> cloud-shape-dark.png[$ne]
Other Info --> In some PHP or NodeJS based back end implementations, in order to obtain sensitive data
it is possible to inject the "[$ne]" string (or other similar ones) that is processed as an
associative array

@jitendra-90
Copy link
Author

How can I try this to attack by Zap Tool

@psiinon
Copy link
Member

psiinon commented May 10, 2024

That is not enough information for us to work with.
We will need the full alert details, including the relevant request and response.
Feel free to obfuscate any sensitive information.

@jitendra-90
Copy link
Author

I am attaching alert screenshot, please have a look
MongoDB-Alert

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Development

No branches or pull requests

4 participants