Advisories for Pypi/Marshmallow package

2018

Information Exposure

In the marshmallow library the schema only option treats an empty list as implying no only option, which allows a request that was intended to expose no fields to instead expose all fields (if the schema is being filtered dynamically using the only option, and there is a user role that produces an empty value for only).