NodeJS/mongoose/1.1.23


Mongoose MongoDB ODM

https://www.npmjs.com/package/mongoose
MIT

5 Security Vulnerabilities

Improper Input Validation in Automattic Mongoose

Published date: 2019-10-22T20:19:54Z
CVE: CVE-2019-17426
Links:

Automattic Mongoose through 5.7.4 allows attackers to bypass access control (in some applications) because any query object with a _bsontype attribute is ignored. For example, adding "_bsontype":"a" can sometimes interfere with a query filter. NOTE: this CVE is about Mongoose's failure to work around this _bsontype special case that exists in older versions of the bson parser (aka the mongodb/js-bson project).

Affected versions: ["0.0.1", "0.0.2", "0.0.3", "0.0.4", "0.0.5", "1.0.0", "1.0.1", "1.0.2", "0.0.6", "1.0.3", "1.0.4", "1.0.5", "1.0.6", "1.0.7", "1.0.8", "1.0.10", "1.0.11", "1.0.12", "1.0.13", "1.0.14", "1.0.15", "1.0.16", "1.1.0", "1.1.1", "1.1.2", "1.1.3", "1.1.4", "1.1.5", "1.1.6", "1.1.7", "1.1.8", "1.1.9", "1.1.10", "1.1.11", "1.1.12", "1.1.13", "1.1.14", "1.1.15", "1.1.16", "1.1.17", "1.1.18", "1.1.19", "1.1.20", "1.1.21", "1.1.22", "1.1.23", "1.1.24", "1.1.25", "1.2.0", "1.3.0", "1.3.1", "1.3.2", "1.3.3", "1.3.4", "1.3.5", "1.3.6", "1.3.7", "1.4.0", "1.5.0", "1.6.0", "1.7.2", "1.7.3", "1.7.4", "1.8.0", "1.8.1", "1.8.2", "1.8.3", "1.8.4", "2.0.0", "2.0.1", "2.0.2", "2.0.3", "2.0.4", "2.1.0", "2.1.1", "2.1.2", "2.1.3", "2.1.4", "2.2.0", "2.2.1", "2.2.2", "2.2.3", "2.2.4", "2.3.0", "2.3.1", "2.3.2", "2.3.3", "2.3.4", "2.3.5", "2.3.6", "2.3.7", "2.3.8", "2.3.9", "2.3.10", "2.3.11", "2.3.12", "2.3.13", "2.4.0", "2.4.1", "2.4.2", "2.4.3", "2.4.4", "2.4.5", "2.4.6", "2.4.7", "2.4.8", "2.4.9", "2.4.10", "2.5.0", "2.5.1", "2.5.2", "2.5.3", "2.5.4", "2.5.5", "2.5.6", "2.5.7", "2.5.8", "2.5.9", "2.5.10", "2.5.11", "2.5.12", "2.5.13", "2.5.14", "2.6.0", "2.6.1", "2.6.2", "2.6.3", "2.6.4", "2.6.5", "2.6.6", "2.6.7", "2.6.8", "2.7.0", "2.7.1", "2.7.2", "2.7.4", "2.7.3", "3.0.0", "3.0.1", "3.0.2", "2.8.0", "3.0.3", "3.1.0", "2.8.1", "3.1.1", "2.8.2", "2.8.3", "2.9.0", "3.2.0", "2.9.1", "3.2.1", "2.9.2", "3.2.2", "3.3.0", "3.3.1", "2.9.3", "3.4.0", "2.9.4", "2.9.5", "3.5.0", "3.5.1", "3.5.2", "3.5.3", "2.9.6", "2.9.7", "3.5.4", "3.5.5", "2.9.8", "2.9.9", "3.5.6", "3.5.7", "3.5.8", "2.9.10", "3.5.9", "3.6.2", "3.5.10", "3.6.3", "3.5.11", "3.6.4", "3.6.5", "3.6.6", "3.6.7", "3.5.12", "3.6.8", "3.6.9", "3.6.10", "3.5.13", "3.5.14", "3.6.11", "3.6.12", "3.6.13", "3.6.14", "3.6.15", "3.5.15", "3.7.0", "3.6.16", "3.5.16", "3.6.17", "3.7.2", "3.0.0-alpha1", "3.0.0-alpha2", "3.0.0-rc0", "3.6.0-rc0", "3.6.0-rc1", "3.6.18", "3.7.3", "3.6.19", "3.6.20", "3.7.4", "3.8.0", "3.8.1", "3.8.2", "3.8.3", "3.8.4", "3.8.5", "3.8.6", "3.8.7", "3.8.8", "3.8.9", "3.8.10", "3.8.11", "3.9.0", "3.8.12", "3.8.13", "3.8.14", "3.8.15", "3.9.1", "3.8.16", "3.9.2", "3.8.17", "3.9.3", "3.8.18", "3.9.4", "3.8.19", "3.9.5", "3.8.20", "3.9.6", "3.8.21", "3.9.7", "3.8.22", "4.0.0-rc0", "4.0.0-rc1", "3.8.23", "4.0.0-rc2", "3.8.24", "4.0.0-rc3", "3.8.25", "4.0.0-rc4", "4.0.0", "4.0.1", "3.8.26", "3.8.27", "4.0.2", "3.8.28", "4.0.3", "3.8.29", "4.0.4", "3.8.30", "4.0.5", "3.8.31", "4.0.6", "3.8.33", "4.0.7", "3.8.34", "4.0.8", "4.1.0", "4.1.1", "4.1.2", "3.8.35", "4.1.3", "4.1.5", "4.1.6", "4.1.7", "4.1.8", "4.1.9", "4.1.10", "4.1.11", "3.8.36", "4.1.12", "4.2.0", "4.2.1", "4.2.2", "4.2.3", "4.2.4", "4.2.5", "3.8.37", "4.2.6", "4.2.7", "4.2.8", "4.2.9", "4.2.10", "4.3.0", "4.3.1", "4.3.2", "4.3.3", "4.3.4", "3.8.38", "4.3.5", "4.3.6", "3.8.39", "4.3.7", "4.4.0", "4.4.1", "4.4.2", "4.4.3", "4.4.4", "4.4.5", "4.4.6", "4.4.7", "4.4.8", "4.4.9", "4.4.10", "4.4.11", "4.4.12", "4.4.13", "3.8.40", "4.4.14", "4.4.15", "4.4.16", "4.4.17", "4.4.18", "4.4.19", "4.4.20", "4.5.0", "4.5.1", "4.5.2", "4.5.3", "4.5.4", "4.5.5", "4.5.6", "4.5.7", "4.5.8", "4.5.9", "4.5.10", "4.6.0", "4.6.1", "4.6.2", "4.6.3", "4.6.4", "4.6.5", "4.6.6", "4.6.7", "4.6.8", "4.7.0", "4.7.1", "4.7.2", "4.7.3", "4.7.4", "4.7.5-pre", "4.7.5", "4.7.6", "4.7.7", "4.7.8", "4.7.9", "4.8.0", "4.8.1", "4.8.2", "4.8.3", "4.8.4", "4.8.5", "4.8.6", "4.8.7", "4.9.0", "4.9.1", "4.9.2", "4.9.3", "4.9.4", "4.9.5", "4.9.6", "4.9.7", "4.9.8", "4.9.9", "4.9.10", "4.10.0", "4.10.1", "4.10.2", "4.10.3", "4.10.4", "4.10.5", "4.10.6", "4.10.7", "4.10.8", "4.11.0", "4.11.1", "4.11.2", "4.11.3", "4.11.4", "4.11.5", "4.11.6", "4.11.7", "4.11.8", "4.11.9", "4.11.10", "4.11.11", "4.11.12", "4.11.13", "4.11.14", "4.12.0", "4.12.1", "4.12.2", "4.12.3", "4.12.4", "4.12.5", "4.12.6", "4.13.0", "4.13.1", "4.13.2", "4.13.3", "4.13.4", "4.13.5", "4.13.6", "4.13.7", "4.13.8", "4.13.9", "4.13.10", "4.13.11", "4.13.12", "4.13.13", "4.13.14", "4.13.15", "4.13.16", "4.13.17", "4.13.18", "4.13.19", "4.13.20", "5.0.0", "5.0.1", "5.0.2", "5.0.3", "5.0.4", "5.0.5", "5.0.6", "5.0.7", "5.0.8", "5.0.9", "5.0.10", "5.0.11", "5.0.12", "5.0.13", "5.0.14", "5.0.15", "5.0.16", "5.0.17", "5.0.18", "5.1.0", "5.1.1", "5.1.2", "5.1.3", "5.1.4", "5.1.5", "5.1.6", "5.1.7", "5.1.8", "5.2.0", "5.2.1", "5.2.2", "5.2.3", "5.2.4", "5.2.5", "5.2.6", "5.2.7", "5.2.8", "5.2.9", "5.2.10", "5.2.11", "5.2.12", "5.2.13", "5.2.14", "5.2.15", "5.2.16", "5.2.17", "5.2.18", "5.3.0", "5.3.1", "5.3.2", "5.3.3", "5.3.4", "5.3.5", "5.3.6", "5.3.7", "5.3.8", "5.3.9", "5.3.10", "5.3.11", "5.3.12", "5.3.13", "5.3.14", "5.3.15", "5.3.16", "5.4.0", "5.4.1", "5.4.2", "5.4.3", "5.4.4", "5.4.5", "5.4.6", "5.4.7", "5.4.8", "5.4.9", "5.4.10", "5.4.11", "5.4.12", "5.4.13", "5.4.14", "5.4.15", "5.4.16", "5.4.17", "5.4.18", "5.4.19", "5.4.20", "5.4.21", "5.4.22", "5.4.23", "5.5.0", "5.5.1", "5.5.2", "5.5.3", "5.5.4", "5.5.5", "5.5.6", "5.5.7", "5.5.8", "5.5.9", "5.5.10", "5.5.11", "5.5.12", "5.5.13", "5.5.14", "5.5.15", "5.6.0", "5.6.1", "5.6.2", "5.6.3", "5.6.4", "5.6.5", "5.6.6", "5.6.7", "5.6.8", "5.6.9", "5.6.10", "5.6.11", "5.6.12", "5.6.13", "5.7.0", "5.7.1", "5.7.3", "5.7.4"]
Secure versions: [6.0.0-rc0, 6.0.0-rc1, 6.0.0-rc2, 7.0.0-rc0, 7.3.3, 6.11.3, 5.13.20, 7.3.4, 6.11.4, 7.4.0, 7.4.1, 6.11.5, 7.4.2, 7.4.3, 6.11.6, 7.4.4, 6.12.0, 7.4.5, 7.5.0, 7.5.1, 7.5.2, 7.5.3, 7.5.4, 7.6.0, 7.6.1, 6.12.1, 7.6.2, 7.6.3, 5.13.21, 8.0.0-rc0, 6.12.2, 7.6.4, 8.0.0, 6.12.3, 7.6.5, 8.0.1, 7.6.6, 8.0.2, 7.6.7, 8.0.3, 6.12.4, 5.13.22, 6.12.5, 7.6.8, 8.0.4, 8.1.0, 6.12.6, 8.1.1, 8.1.2, 8.1.3, 8.2.0, 7.6.9, 6.12.7, 8.2.1, 7.6.10, 8.2.2, 8.2.3, 8.2.4, 8.3.0, 8.3.1, 6.12.8, 7.6.11, 8.3.2, 8.3.3, 8.3.4, 8.3.5, 8.4.0, 7.6.12, 6.12.9, 8.4.1, 7.6.13, 6.13.0, 8.4.2, 8.4.3, 7.7.0, 8.4.4, 8.4.5, 8.5.0, 8.5.1, 7.8.0, 8.5.2, 8.5.3, 7.8.1, 8.5.4, 8.5.5, 8.6.0, 8.6.1, 6.13.1, 8.6.2, 6.13.2, 8.6.3, 6.13.3, 7.8.2, 8.6.4, 8.7.0, 8.7.1, 8.7.2, 8.7.3, 8.8.0, 8.8.1]
Recommendation: Update to version 8.8.1.

Mongoose Prototype Pollution vulnerability

Published date: 2023-07-17T03:30:20Z
CVE: CVE-2023-3696
Links:

Prototype Pollution in GitHub repository automattic/mongoose prior to 7.3.3, 6.11.3, and 5.13.20.

Affected versions: ["0.0.1", "0.0.2", "0.0.3", "0.0.4", "0.0.5", "1.0.0", "1.0.1", "1.0.2", "0.0.6", "1.0.3", "1.0.4", "1.0.5", "1.0.6", "1.0.7", "1.0.8", "1.0.10", "1.0.11", "1.0.12", "1.0.13", "1.0.14", "1.0.15", "1.0.16", "1.1.0", "1.1.1", "1.1.2", "1.1.3", "1.1.4", "1.1.5", "1.1.6", "1.1.7", "1.1.8", "1.1.9", "1.1.10", "1.1.11", "1.1.12", "1.1.13", "1.1.14", "1.1.15", "1.1.16", "1.1.17", "1.1.18", "1.1.19", "1.1.20", "1.1.21", "1.1.22", "1.1.23", "1.1.24", "1.1.25", "1.2.0", "1.3.0", "1.3.1", "1.3.2", "1.3.3", "1.3.4", "1.3.5", "1.3.6", "1.3.7", "1.4.0", "1.5.0", "1.6.0", "1.7.2", "1.7.3", "1.7.4", "1.8.0", "1.8.1", "1.8.2", "1.8.3", "1.8.4", "2.0.0", "2.0.1", "2.0.2", "2.0.3", "2.0.4", "2.1.0", "2.1.1", "2.1.2", "2.1.3", "2.1.4", "2.2.0", "2.2.1", "2.2.2", "2.2.3", "2.2.4", "2.3.0", "2.3.1", "2.3.2", "2.3.3", "2.3.4", "2.3.5", "2.3.6", "2.3.7", "2.3.8", "2.3.9", "2.3.10", "2.3.11", "2.3.12", "2.3.13", "2.4.0", "2.4.1", "2.4.2", "2.4.3", "2.4.4", "2.4.5", "2.4.6", "2.4.7", "2.4.8", "2.4.9", "2.4.10", "2.5.0", "2.5.1", "2.5.2", "2.5.3", "2.5.4", "2.5.5", "2.5.6", "2.5.7", "2.5.8", "2.5.9", "2.5.10", "2.5.11", "2.5.12", "2.5.13", "2.5.14", "2.6.0", "2.6.1", "2.6.2", "2.6.3", "2.6.4", "2.6.5", "2.6.6", "2.6.7", "2.6.8", "2.7.0", "2.7.1", "2.7.2", "2.7.4", "2.7.3", "3.0.0", "3.0.1", "3.0.2", "2.8.0", "3.0.3", "3.1.0", "2.8.1", "3.1.1", "2.8.2", "2.8.3", "2.9.0", "3.2.0", "2.9.1", "3.2.1", "2.9.2", "3.2.2", "3.3.0", "3.3.1", "2.9.3", "3.4.0", "2.9.4", "2.9.5", "3.5.0", "3.5.1", "3.5.2", "3.5.3", "2.9.6", "2.9.7", "3.5.4", "3.5.5", "2.9.8", "2.9.9", "3.5.6", "3.5.7", "3.5.8", "2.9.10", "3.5.9", "3.6.2", "3.5.10", "3.6.3", "3.5.11", "3.6.4", "3.6.5", "3.6.6", "3.6.7", "3.5.12", "3.6.8", "3.6.9", "3.6.10", "3.5.13", "3.5.14", "3.6.11", "3.6.12", "3.6.13", "3.6.14", "3.6.15", "3.5.15", "3.7.0", "3.6.16", "3.5.16", "3.6.17", "3.7.2", "3.0.0-alpha1", "3.0.0-alpha2", "3.0.0-rc0", "3.6.0-rc0", "3.6.0-rc1", "3.6.18", "3.7.3", "3.6.19", "3.6.20", "3.7.4", "3.8.0", "3.8.1", "3.8.2", "3.8.3", "3.8.4", "3.8.5", "3.8.6", "3.8.7", "3.8.8", "3.8.9", "3.8.10", "3.8.11", "3.9.0", "3.8.12", "3.8.13", "3.8.14", "3.8.15", "3.9.1", "3.8.16", "3.9.2", "3.8.17", "3.9.3", "3.8.18", "3.9.4", "3.8.19", "3.9.5", "3.8.20", "3.9.6", "3.8.21", "3.9.7", "3.8.22", "4.0.0-rc0", "4.0.0-rc1", "3.8.23", "4.0.0-rc2", "3.8.24", "4.0.0-rc3", "3.8.25", "4.0.0-rc4", "4.0.0", "4.0.1", "3.8.26", "3.8.27", "4.0.2", "3.8.28", "4.0.3", "3.8.29", "4.0.4", "3.8.30", "4.0.5", "3.8.31", "4.0.6", "3.8.33", "4.0.7", "3.8.34", "4.0.8", "4.1.0", "4.1.1", "4.1.2", "3.8.35", "4.1.3", "4.1.5", "4.1.6", "4.1.7", "4.1.8", "4.1.9", "4.1.10", "4.1.11", "3.8.36", "4.1.12", "4.2.0", "4.2.1", "4.2.2", "4.2.3", "4.2.4", "4.2.5", "3.8.37", "4.2.6", "4.2.7", "4.2.8", "4.2.9", "4.2.10", "4.3.0", "4.3.1", "4.3.2", "4.3.3", "4.3.4", "3.8.38", "4.3.5", "4.3.6", "3.8.39", "4.3.7", "4.4.0", "4.4.1", "4.4.2", "4.4.3", "4.4.4", "4.4.5", "4.4.6", "4.4.7", "4.4.8", "4.4.9", "4.4.10", "4.4.11", "4.4.12", "4.4.13", "3.8.40", "4.4.14", "4.4.15", "4.4.16", "4.4.17", "4.4.18", "4.4.19", "4.4.20", "4.5.0", "4.5.1", "4.5.2", "4.5.3", "4.5.4", "4.5.5", "4.5.6", "4.5.7", "4.5.8", "4.5.9", "4.5.10", "4.6.0", "4.6.1", "4.6.2", "4.6.3", "4.6.4", "4.6.5", "4.6.6", "4.6.7", "4.6.8", "4.7.0", "4.7.1", "4.7.2", "4.7.3", "4.7.4", "4.7.5-pre", "4.7.5", "4.7.6", "4.7.7", "4.7.8", "4.7.9", "4.8.0", "4.8.1", "4.8.2", "4.8.3", "4.8.4", "4.8.5", "4.8.6", "4.8.7", "4.9.0", "4.9.1", "4.9.2", "4.9.3", "4.9.4", "4.9.5", "4.9.6", "4.9.7", "4.9.8", "4.9.9", "4.9.10", "4.10.0", "4.10.1", "4.10.2", "4.10.3", "4.10.4", "4.10.5", "4.10.6", "4.10.7", "4.10.8", "4.11.0", "4.11.1", "4.11.2", "4.11.3", "4.11.4", "4.11.5", "4.11.6", "4.11.7", "4.11.8", "4.11.9", "4.11.10", "4.11.11", "4.11.12", "4.11.13", "4.11.14", "4.12.0", "4.12.1", "4.12.2", "4.12.3", "4.12.4", "4.12.5", "4.12.6", "4.13.0", "4.13.1", "4.13.2", "4.13.3", "4.13.4", "4.13.5", "4.13.6", "4.13.7", "4.13.8", "5.0.0-rc0", "5.0.0-rc1", "5.0.0-rc2", "4.13.9", "5.0.0", "5.0.1", "4.13.10", "5.0.2", "5.0.3", "4.13.11", "5.0.4", "5.0.5", "5.0.6", "5.0.7", "5.0.8", "5.0.9", "5.0.10", "4.13.12", "5.0.11", "5.0.12", "5.0.13", "5.0.14", "5.0.15", "5.0.16", "5.0.17", "5.0.18", "5.1.0", "5.1.1", "4.13.13", "5.1.2", "4.13.14", "5.1.3", "5.1.4", "5.1.5", "5.1.6", "5.1.7", "5.1.8", "5.2.0", "5.2.1", "5.2.2", "5.2.3", "5.2.4", "5.2.5", "5.2.6", "5.2.7", "5.2.8", "4.13.15", "5.2.9", "5.2.10", "4.13.16", "5.2.11", "4.13.17", "5.2.12", "5.2.13", "5.2.14", "5.2.15", "5.2.16", "5.2.17", "5.2.18", "5.3.0", "5.3.1", "5.3.2", "5.3.3", "5.3.4", "5.3.5", "5.3.6", "5.3.7", "5.3.8", "5.3.9", "5.3.10", "5.3.11", "5.3.12", "5.3.13", "5.3.14", "5.3.15", "5.3.16", "5.4.0", "5.4.1", "5.4.2", "5.4.3", "5.4.4", "5.4.5", "4.13.18", "5.4.6", "5.4.7", "5.4.8", "5.4.9", "5.4.10", "5.4.11", "5.4.12", "5.4.13", "5.4.14", "5.4.15", "5.4.16", "5.4.17", "5.4.18", "5.4.19", "5.4.20", "5.4.21", "5.4.22", "5.4.23", "5.5.0", "5.5.1", "5.5.2", "5.5.3", "5.5.4", "5.5.5", "5.5.6", "5.5.7", "5.5.8", "5.5.9", "5.5.10", "5.5.11", "5.5.12", "5.5.13", "5.5.14", "5.5.15", "5.6.0", "5.6.1", "5.6.2", "5.6.3", "5.6.4", "5.6.5", "4.13.19", "5.6.6", "5.6.7", "5.6.8", "5.6.9", "5.6.10", "5.6.11", "5.6.12", "5.6.13", "5.7.0", "5.7.1", "5.7.3", "5.7.4", "5.7.5", "5.7.6", "5.7.7", "5.7.8", "5.7.9", "5.7.10", "5.7.11", "5.7.12", "5.7.13", "5.7.14", "5.8.0", "5.8.1", "5.8.2", "5.8.3", "5.8.4", "5.8.5", "4.13.20", "5.8.6", "5.8.7", "5.8.9", "5.8.10", "5.8.11", "5.8.12", "5.8.13", "5.9.0", "5.9.1", "5.9.2", "5.9.3", "5.9.4", "5.9.5", "5.9.6", "5.9.7", "5.9.9", "5.9.10", "5.9.11", "5.9.12", "5.9.13", "5.9.14", "5.9.15", "5.9.16", "5.9.17", "5.9.18", "5.9.19", "5.9.20", "5.9.21", "5.9.22", "5.9.23", "4.13.21", "5.9.24", "5.9.25", "5.9.26", "5.9.27", "5.9.28", "5.9.29", "5.10.0", "5.10.1", "5.10.2", "5.10.3", "5.10.4", "5.10.5", "5.10.6", "5.10.7", "5.10.8", "5.10.9", "5.10.10", "5.10.11", "5.10.12", "5.10.13", "5.10.14", "5.10.15", "5.10.16", "5.10.17", "5.10.18", "5.10.19", "5.11.0", "5.11.1", "5.11.2", "5.11.3", "5.11.4", "5.11.5", "5.11.6", "5.11.7", "5.11.8", "5.11.9", "5.11.10", "5.11.11", "5.11.12", "5.11.13", "5.11.14", "5.11.15", "5.11.16", "5.11.17", "5.11.18", "5.11.19", "5.11.20", "5.12.0", "5.12.1", "5.12.2", "5.12.3", "5.12.4", "5.12.5", "5.12.6", "5.12.7", "5.12.8", "5.12.9", "5.12.10", "5.12.11", "5.12.12", "5.12.13", "5.12.14", "5.12.15", "5.13.0", "5.13.1", "5.13.2", "5.13.3", "5.13.4", "5.13.5", "5.13.6", "5.13.7", "5.13.8", "5.13.9", "5.13.10", "5.13.11", "5.13.12", "5.13.13", "5.13.14", "5.13.15", "5.13.16", "5.13.17", "5.13.18", "5.13.19", "6.0.0", "6.0.1", "6.0.2", "6.0.3", "6.0.4", "6.0.5", "6.0.6", "6.0.7", "6.0.8", "6.0.9", "6.0.10", "6.0.11", "6.0.12", "6.0.13", "6.0.14", "6.0.15", "6.1.0", "6.1.1", "6.1.2", "6.1.3", "6.1.4", "6.1.5", "6.1.6", "6.1.7", "6.1.8", "6.1.9", "6.1.10", "6.2.0", "6.2.1", "6.2.2", "6.2.3", "6.2.4", "6.2.5", "6.2.6", "6.2.7", "6.2.8", "6.2.9", "6.2.10", "6.2.11", "6.3.0", "6.3.1", "6.3.2", "6.3.3", "6.3.4", "6.3.5", "6.3.6", "6.3.7", "6.3.8", "6.3.9", "6.4.0", "6.4.1", "6.4.2", "6.4.3", "6.4.4", "6.4.5", "6.4.6", "6.4.7", "6.5.0", "6.5.1", "6.5.2", "6.5.3", "6.5.4", "6.5.5", "6.6.0", "6.6.1", "6.6.2", "6.6.3", "6.6.4", "6.6.5", "6.6.6", "6.6.7", "6.7.0", "6.7.1", "6.7.2", "6.7.3", "6.7.4", "6.7.5", "6.8.0", "6.8.1", "6.8.2", "6.8.3", "6.8.4", "6.9.0", "6.9.1", "6.9.2", "6.9.3", "6.10.0", "6.10.1", "6.10.2", "6.10.3", "6.10.4", "6.10.5", "6.11.0", "6.11.1", "6.11.2", "7.0.0", "7.0.1", "7.0.2", "7.0.3", "7.0.4", "7.0.5", "7.1.0", "7.1.1", "7.1.2", "7.2.0", "7.2.1", "7.2.2", "7.2.3", "7.2.4", "7.3.0", "7.3.1", "7.3.2"]
Secure versions: [6.0.0-rc0, 6.0.0-rc1, 6.0.0-rc2, 7.0.0-rc0, 7.3.3, 6.11.3, 5.13.20, 7.3.4, 6.11.4, 7.4.0, 7.4.1, 6.11.5, 7.4.2, 7.4.3, 6.11.6, 7.4.4, 6.12.0, 7.4.5, 7.5.0, 7.5.1, 7.5.2, 7.5.3, 7.5.4, 7.6.0, 7.6.1, 6.12.1, 7.6.2, 7.6.3, 5.13.21, 8.0.0-rc0, 6.12.2, 7.6.4, 8.0.0, 6.12.3, 7.6.5, 8.0.1, 7.6.6, 8.0.2, 7.6.7, 8.0.3, 6.12.4, 5.13.22, 6.12.5, 7.6.8, 8.0.4, 8.1.0, 6.12.6, 8.1.1, 8.1.2, 8.1.3, 8.2.0, 7.6.9, 6.12.7, 8.2.1, 7.6.10, 8.2.2, 8.2.3, 8.2.4, 8.3.0, 8.3.1, 6.12.8, 7.6.11, 8.3.2, 8.3.3, 8.3.4, 8.3.5, 8.4.0, 7.6.12, 6.12.9, 8.4.1, 7.6.13, 6.13.0, 8.4.2, 8.4.3, 7.7.0, 8.4.4, 8.4.5, 8.5.0, 8.5.1, 7.8.0, 8.5.2, 8.5.3, 7.8.1, 8.5.4, 8.5.5, 8.6.0, 8.6.1, 6.13.1, 8.6.2, 6.13.2, 8.6.3, 6.13.3, 7.8.2, 8.6.4, 8.7.0, 8.7.1, 8.7.2, 8.7.3, 8.8.0, 8.8.1]
Recommendation: Update to version 8.8.1.

automattic/mongoose vulnerable to Prototype pollution via Schema.path

Published date: 2022-07-29T00:00:18Z
CVE: CVE-2022-2564
Links:

Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Affected versions of this package are vulnerable to Prototype Pollution. The Schema.path() function is vulnerable to prototype pollution when setting the schema object. This vulnerability allows modification of the Object prototype and could be manipulated into a Denial of Service (DoS) attack.

Affected versions: ["0.0.1", "0.0.2", "0.0.3", "0.0.4", "0.0.5", "1.0.0", "1.0.1", "1.0.2", "0.0.6", "1.0.3", "1.0.4", "1.0.5", "1.0.6", "1.0.7", "1.0.8", "1.0.10", "1.0.11", "1.0.12", "1.0.13", "1.0.14", "1.0.15", "1.0.16", "1.1.0", "1.1.1", "1.1.2", "1.1.3", "1.1.4", "1.1.5", "1.1.6", "1.1.7", "1.1.8", "1.1.9", "1.1.10", "1.1.11", "1.1.12", "1.1.13", "1.1.14", "1.1.15", "1.1.16", "1.1.17", "1.1.18", "1.1.19", "1.1.20", "1.1.21", "1.1.22", "1.1.23", "1.1.24", "1.1.25", "1.2.0", "1.3.0", "1.3.1", "1.3.2", "1.3.3", "1.3.4", "1.3.5", "1.3.6", "1.3.7", "1.4.0", "1.5.0", "1.6.0", "1.7.2", "1.7.3", "1.7.4", "1.8.0", "1.8.1", "1.8.2", "1.8.3", "1.8.4", "2.0.0", "2.0.1", "2.0.2", "2.0.3", "2.0.4", "2.1.0", "2.1.1", "2.1.2", "2.1.3", "2.1.4", "2.2.0", "2.2.1", "2.2.2", "2.2.3", "2.2.4", "2.3.0", "2.3.1", "2.3.2", "2.3.3", "2.3.4", "2.3.5", "2.3.6", "2.3.7", "2.3.8", "2.3.9", "2.3.10", "2.3.11", "2.3.12", "2.3.13", "2.4.0", "2.4.1", "2.4.2", "2.4.3", "2.4.4", "2.4.5", "2.4.6", "2.4.7", "2.4.8", "2.4.9", "2.4.10", "2.5.0", "2.5.1", "2.5.2", "2.5.3", "2.5.4", "2.5.5", "2.5.6", "2.5.7", "2.5.8", "2.5.9", "2.5.10", "2.5.11", "2.5.12", "2.5.13", "2.5.14", "2.6.0", "2.6.1", "2.6.2", "2.6.3", "2.6.4", "2.6.5", "2.6.6", "2.6.7", "2.6.8", "2.7.0", "2.7.1", "2.7.2", "2.7.4", "2.7.3", "3.0.0", "3.0.1", "3.0.2", "2.8.0", "3.0.3", "3.1.0", "2.8.1", "3.1.1", "2.8.2", "2.8.3", "2.9.0", "3.2.0", "2.9.1", "3.2.1", "2.9.2", "3.2.2", "3.3.0", "3.3.1", "2.9.3", "3.4.0", "2.9.4", "2.9.5", "3.5.0", "3.5.1", "3.5.2", "3.5.3", "2.9.6", "2.9.7", "3.5.4", "3.5.5", "2.9.8", "2.9.9", "3.5.6", "3.5.7", "3.5.8", "2.9.10", "3.5.9", "3.6.2", "3.5.10", "3.6.3", "3.5.11", "3.6.4", "3.6.5", "3.6.6", "3.6.7", "3.5.12", "3.6.8", "3.6.9", "3.6.10", "3.5.13", "3.5.14", "3.6.11", "3.6.12", "3.6.13", "3.6.14", "3.6.15", "3.5.15", "3.7.0", "3.6.16", "3.5.16", "3.6.17", "3.7.2", "3.0.0-alpha1", "3.0.0-alpha2", "3.0.0-rc0", "3.6.0-rc0", "3.6.0-rc1", "3.6.18", "3.7.3", "3.6.19", "3.6.20", "3.7.4", "3.8.0", "3.8.1", "3.8.2", "3.8.3", "3.8.4", "3.8.5", "3.8.6", "3.8.7", "3.8.8", "3.8.9", "3.8.10", "3.8.11", "3.9.0", "3.8.12", "3.8.13", "3.8.14", "3.8.15", "3.9.1", "3.8.16", "3.9.2", "3.8.17", "3.9.3", "3.8.18", "3.9.4", "3.8.19", "3.9.5", "3.8.20", "3.9.6", "3.8.21", "3.9.7", "3.8.22", "4.0.0-rc0", "4.0.0-rc1", "3.8.23", "4.0.0-rc2", "3.8.24", "4.0.0-rc3", "3.8.25", "4.0.0-rc4", "4.0.0", "4.0.1", "3.8.26", "3.8.27", "4.0.2", "3.8.28", "4.0.3", "3.8.29", "4.0.4", "3.8.30", "4.0.5", "3.8.31", "4.0.6", "3.8.33", "4.0.7", "3.8.34", "4.0.8", "4.1.0", "4.1.1", "4.1.2", "3.8.35", "4.1.3", "4.1.5", "4.1.6", "4.1.7", "4.1.8", "4.1.9", "4.1.10", "4.1.11", "3.8.36", "4.1.12", "4.2.0", "4.2.1", "4.2.2", "4.2.3", "4.2.4", "4.2.5", "3.8.37", "4.2.6", "4.2.7", "4.2.8", "4.2.9", "4.2.10", "4.3.0", "4.3.1", "4.3.2", "4.3.3", "4.3.4", "3.8.38", "4.3.5", "4.3.6", "3.8.39", "4.3.7", "4.4.0", "4.4.1", "4.4.2", "4.4.3", "4.4.4", "4.4.5", "4.4.6", "4.4.7", "4.4.8", "4.4.9", "4.4.10", "4.4.11", "4.4.12", "4.4.13", "3.8.40", "4.4.14", "4.4.15", "4.4.16", "4.4.17", "4.4.18", "4.4.19", "4.4.20", "4.5.0", "4.5.1", "4.5.2", "4.5.3", "4.5.4", "4.5.5", "4.5.6", "4.5.7", "4.5.8", "4.5.9", "4.5.10", "4.6.0", "4.6.1", "4.6.2", "4.6.3", "4.6.4", "4.6.5", "4.6.6", "4.6.7", "4.6.8", "4.7.0", "4.7.1", "4.7.2", "4.7.3", "4.7.4", "4.7.5-pre", "4.7.5", "4.7.6", "4.7.7", "4.7.8", "4.7.9", "4.8.0", "4.8.1", "4.8.2", "4.8.3", "4.8.4", "4.8.5", "4.8.6", "4.8.7", "4.9.0", "4.9.1", "4.9.2", "4.9.3", "4.9.4", "4.9.5", "4.9.6", "4.9.7", "4.9.8", "4.9.9", "4.9.10", "4.10.0", "4.10.1", "4.10.2", "4.10.3", "4.10.4", "4.10.5", "4.10.6", "4.10.7", "4.10.8", "4.11.0", "4.11.1", "4.11.2", "4.11.3", "4.11.4", "4.11.5", "4.11.6", "4.11.7", "4.11.8", "4.11.9", "4.11.10", "4.11.11", "4.11.12", "4.11.13", "4.11.14", "4.12.0", "4.12.1", "4.12.2", "4.12.3", "4.12.4", "4.12.5", "4.12.6", "4.13.0", "4.13.1", "4.13.2", "4.13.3", "4.13.4", "4.13.5", "4.13.6", "4.13.7", "4.13.8", "5.0.0-rc0", "5.0.0-rc1", "5.0.0-rc2", "4.13.9", "5.0.0", "5.0.1", "4.13.10", "5.0.2", "5.0.3", "4.13.11", "5.0.4", "5.0.5", "5.0.6", "5.0.7", "5.0.8", "5.0.9", "5.0.10", "4.13.12", "5.0.11", "5.0.12", "5.0.13", "5.0.14", "5.0.15", "5.0.16", "5.0.17", "5.0.18", "5.1.0", "5.1.1", "4.13.13", "5.1.2", "4.13.14", "5.1.3", "5.1.4", "5.1.5", "5.1.6", "5.1.7", "5.1.8", "5.2.0", "5.2.1", "5.2.2", "5.2.3", "5.2.4", "5.2.5", "5.2.6", "5.2.7", "5.2.8", "4.13.15", "5.2.9", "5.2.10", "4.13.16", "5.2.11", "4.13.17", "5.2.12", "5.2.13", "5.2.14", "5.2.15", "5.2.16", "5.2.17", "5.2.18", "5.3.0", "5.3.1", "5.3.2", "5.3.3", "5.3.4", "5.3.5", "5.3.6", "5.3.7", "5.3.8", "5.3.9", "5.3.10", "5.3.11", "5.3.12", "5.3.13", "5.3.14", "5.3.15", "5.3.16", "5.4.0", "5.4.1", "5.4.2", "5.4.3", "5.4.4", "5.4.5", "4.13.18", "5.4.6", "5.4.7", "5.4.8", "5.4.9", "5.4.10", "5.4.11", "5.4.12", "5.4.13", "5.4.14", "5.4.15", "5.4.16", "5.4.17", "5.4.18", "5.4.19", "5.4.20", "5.4.21", "5.4.22", "5.4.23", "5.5.0", "5.5.1", "5.5.2", "5.5.3", "5.5.4", "5.5.5", "5.5.6", "5.5.7", "5.5.8", "5.5.9", "5.5.10", "5.5.11", "5.5.12", "5.5.13", "5.5.14", "5.5.15", "5.6.0", "5.6.1", "5.6.2", "5.6.3", "5.6.4", "5.6.5", "4.13.19", "5.6.6", "5.6.7", "5.6.8", "5.6.9", "5.6.10", "5.6.11", "5.6.12", "5.6.13", "5.7.0", "5.7.1", "5.7.3", "5.7.4", "5.7.5", "5.7.6", "5.7.7", "5.7.8", "5.7.9", "5.7.10", "5.7.11", "5.7.12", "5.7.13", "5.7.14", "5.8.0", "5.8.1", "5.8.2", "5.8.3", "5.8.4", "5.8.5", "4.13.20", "5.8.6", "5.8.7", "5.8.9", "5.8.10", "5.8.11", "5.8.12", "5.8.13", "5.9.0", "5.9.1", "5.9.2", "5.9.3", "5.9.4", "5.9.5", "5.9.6", "5.9.7", "5.9.9", "5.9.10", "5.9.11", "5.9.12", "5.9.13", "5.9.14", "5.9.15", "5.9.16", "5.9.17", "5.9.18", "5.9.19", "5.9.20", "5.9.21", "5.9.22", "5.9.23", "4.13.21", "5.9.24", "5.9.25", "5.9.26", "5.9.27", "5.9.28", "5.9.29", "5.10.0", "5.10.1", "5.10.2", "5.10.3", "5.10.4", "5.10.5", "5.10.6", "5.10.7", "5.10.8", "5.10.9", "5.10.10", "5.10.11", "5.10.12", "5.10.13", "5.10.14", "5.10.15", "5.10.16", "5.10.17", "5.10.18", "5.10.19", "5.11.0", "5.11.1", "5.11.2", "5.11.3", "5.11.4", "5.11.5", "5.11.6", "5.11.7", "5.11.8", "5.11.9", "5.11.10", "5.11.11", "5.11.12", "5.11.13", "5.11.14", "5.11.15", "5.11.16", "5.11.17", "5.11.18", "5.11.19", "5.11.20", "5.12.0", "5.12.1", "5.12.2", "5.12.3", "5.12.4", "5.12.5", "5.12.6", "5.12.7", "5.12.8", "5.12.9", "5.12.10", "5.12.11", "5.12.12", "5.12.13", "5.12.14", "5.12.15", "5.13.0", "5.13.1", "5.13.2", "5.13.3", "5.13.4", "5.13.5", "5.13.6", "5.13.7", "5.13.8", "5.13.9", "5.13.10", "5.13.11", "5.13.12", "5.13.13", "5.13.14", "6.0.0", "6.0.1", "6.0.2", "6.0.3", "6.0.4", "6.0.5", "6.0.6", "6.0.7", "6.0.8", "6.0.9", "6.0.10", "6.0.11", "6.0.12", "6.0.13", "6.0.14", "6.0.15", "6.1.0", "6.1.1", "6.1.2", "6.1.3", "6.1.4", "6.1.5", "6.1.6", "6.1.7", "6.1.8", "6.1.9", "6.1.10", "6.2.0", "6.2.1", "6.2.2", "6.2.3", "6.2.4", "6.2.5", "6.2.6", "6.2.7", "6.2.8", "6.2.9", "6.2.10", "6.2.11", "6.3.0", "6.3.1", "6.3.2", "6.3.3", "6.3.4", "6.3.5", "6.3.6", "6.3.7", "6.3.8", "6.3.9", "6.4.0", "6.4.1", "6.4.2", "6.4.3", "6.4.4", "6.4.5"]
Secure versions: [6.0.0-rc0, 6.0.0-rc1, 6.0.0-rc2, 7.0.0-rc0, 7.3.3, 6.11.3, 5.13.20, 7.3.4, 6.11.4, 7.4.0, 7.4.1, 6.11.5, 7.4.2, 7.4.3, 6.11.6, 7.4.4, 6.12.0, 7.4.5, 7.5.0, 7.5.1, 7.5.2, 7.5.3, 7.5.4, 7.6.0, 7.6.1, 6.12.1, 7.6.2, 7.6.3, 5.13.21, 8.0.0-rc0, 6.12.2, 7.6.4, 8.0.0, 6.12.3, 7.6.5, 8.0.1, 7.6.6, 8.0.2, 7.6.7, 8.0.3, 6.12.4, 5.13.22, 6.12.5, 7.6.8, 8.0.4, 8.1.0, 6.12.6, 8.1.1, 8.1.2, 8.1.3, 8.2.0, 7.6.9, 6.12.7, 8.2.1, 7.6.10, 8.2.2, 8.2.3, 8.2.4, 8.3.0, 8.3.1, 6.12.8, 7.6.11, 8.3.2, 8.3.3, 8.3.4, 8.3.5, 8.4.0, 7.6.12, 6.12.9, 8.4.1, 7.6.13, 6.13.0, 8.4.2, 8.4.3, 7.7.0, 8.4.4, 8.4.5, 8.5.0, 8.5.1, 7.8.0, 8.5.2, 8.5.3, 7.8.1, 8.5.4, 8.5.5, 8.6.0, 8.6.1, 6.13.1, 8.6.2, 6.13.2, 8.6.3, 6.13.3, 7.8.2, 8.6.4, 8.7.0, 8.7.1, 8.7.2, 8.7.3, 8.8.0, 8.8.1]
Recommendation: Update to version 8.8.1.

Mongoose Vulnerable to Prototype Pollution in Schema Object

Published date: 2022-08-27T00:00:54Z
CVE: CVE-2022-24304
Links:

Description

Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment.

Affected versions of this package are vulnerable to Prototype Pollution. The Schema.path() function is vulnerable to prototype pollution when setting the schema object. This vulnerability allows modification of the Object prototype and could be manipulated into a Denial of Service (DoS) attack.

Proof of Concept

// poc.js
const mongoose = require('mongoose');
const schema = new mongoose.Schema();

malicious_payload = '__proto__.toString'

schema.path(malicious_payload, [String])

x = {}
console.log(x.toString()) // crashed (Denial of service (DoS) attack)

Impact

This vulnerability can be manipulated to exploit other types of attacks, such as Denial of service (DoS), Remote Code Execution, or Property Injection.

Affected versions: ["0.0.1", "0.0.2", "0.0.3", "0.0.4", "0.0.5", "1.0.0", "1.0.1", "1.0.2", "0.0.6", "1.0.3", "1.0.4", "1.0.5", "1.0.6", "1.0.7", "1.0.8", "1.0.10", "1.0.11", "1.0.12", "1.0.13", "1.0.14", "1.0.15", "1.0.16", "1.1.0", "1.1.1", "1.1.2", "1.1.3", "1.1.4", "1.1.5", "1.1.6", "1.1.7", "1.1.8", "1.1.9", "1.1.10", "1.1.11", "1.1.12", "1.1.13", "1.1.14", "1.1.15", "1.1.16", "1.1.17", "1.1.18", "1.1.19", "1.1.20", "1.1.21", "1.1.22", "1.1.23", "1.1.24", "1.1.25", "1.2.0", "1.3.0", "1.3.1", "1.3.2", "1.3.3", "1.3.4", "1.3.5", "1.3.6", "1.3.7", "1.4.0", "1.5.0", "1.6.0", "1.7.2", "1.7.3", "1.7.4", "1.8.0", "1.8.1", "1.8.2", "1.8.3", "1.8.4", "2.0.0", "2.0.1", "2.0.2", "2.0.3", "2.0.4", "2.1.0", "2.1.1", "2.1.2", "2.1.3", "2.1.4", "2.2.0", "2.2.1", "2.2.2", "2.2.3", "2.2.4", "2.3.0", "2.3.1", "2.3.2", "2.3.3", "2.3.4", "2.3.5", "2.3.6", "2.3.7", "2.3.8", "2.3.9", "2.3.10", "2.3.11", "2.3.12", "2.3.13", "2.4.0", "2.4.1", "2.4.2", "2.4.3", "2.4.4", "2.4.5", "2.4.6", "2.4.7", "2.4.8", "2.4.9", "2.4.10", "2.5.0", "2.5.1", "2.5.2", "2.5.3", "2.5.4", "2.5.5", "2.5.6", "2.5.7", "2.5.8", "2.5.9", "2.5.10", "2.5.11", "2.5.12", "2.5.13", "2.5.14", "2.6.0", "2.6.1", "2.6.2", "2.6.3", "2.6.4", "2.6.5", "2.6.6", "2.6.7", "2.6.8", "2.7.0", "2.7.1", "2.7.2", "2.7.4", "2.7.3", "3.0.0", "3.0.1", "3.0.2", "2.8.0", "3.0.3", "3.1.0", "2.8.1", "3.1.1", "2.8.2", "2.8.3", "2.9.0", "3.2.0", "2.9.1", "3.2.1", "2.9.2", "3.2.2", "3.3.0", "3.3.1", "2.9.3", "3.4.0", "2.9.4", "2.9.5", "3.5.0", "3.5.1", "3.5.2", "3.5.3", "2.9.6", "2.9.7", "3.5.4", "3.5.5", "2.9.8", "2.9.9", "3.5.6", "3.5.7", "3.5.8", "2.9.10", "3.5.9", "3.6.2", "3.5.10", "3.6.3", "3.5.11", "3.6.4", "3.6.5", "3.6.6", "3.6.7", "3.5.12", "3.6.8", "3.6.9", "3.6.10", "3.5.13", "3.5.14", "3.6.11", "3.6.12", "3.6.13", "3.6.14", "3.6.15", "3.5.15", "3.7.0", "3.6.16", "3.5.16", "3.6.17", "3.7.2", "3.0.0-alpha1", "3.0.0-alpha2", "3.0.0-rc0", "3.6.0-rc0", "3.6.0-rc1", "3.6.18", "3.7.3", "3.6.19", "3.6.20", "3.7.4", "3.8.0", "3.8.1", "3.8.2", "3.8.3", "3.8.4", "3.8.5", "3.8.6", "3.8.7", "3.8.8", "3.8.9", "3.8.10", "3.8.11", "3.9.0", "3.8.12", "3.8.13", "3.8.14", "3.8.15", "3.9.1", "3.8.16", "3.9.2", "3.8.17", "3.9.3", "3.8.18", "3.9.4", "3.8.19", "3.9.5", "3.8.20", "3.9.6", "3.8.21", "3.9.7", "3.8.22", "4.0.0-rc0", "4.0.0-rc1", "3.8.23", "4.0.0-rc2", "3.8.24", "4.0.0-rc3", "3.8.25", "4.0.0-rc4", "4.0.0", "4.0.1", "3.8.26", "3.8.27", "4.0.2", "3.8.28", "4.0.3", "3.8.29", "4.0.4", "3.8.30", "4.0.5", "3.8.31", "4.0.6", "3.8.33", "4.0.7", "3.8.34", "4.0.8", "4.1.0", "4.1.1", "4.1.2", "3.8.35", "4.1.3", "4.1.5", "4.1.6", "4.1.7", "4.1.8", "4.1.9", "4.1.10", "4.1.11", "3.8.36", "4.1.12", "4.2.0", "4.2.1", "4.2.2", "4.2.3", "4.2.4", "4.2.5", "3.8.37", "4.2.6", "4.2.7", "4.2.8", "4.2.9", "4.2.10", "4.3.0", "4.3.1", "4.3.2", "4.3.3", "4.3.4", "3.8.38", "4.3.5", "4.3.6", "3.8.39", "4.3.7", "4.4.0", "4.4.1", "4.4.2", "4.4.3", "4.4.4", "4.4.5", "4.4.6", "4.4.7", "4.4.8", "4.4.9", "4.4.10", "4.4.11", "4.4.12", "4.4.13", "3.8.40", "4.4.14", "4.4.15", "4.4.16", "4.4.17", "4.4.18", "4.4.19", "4.4.20", "4.5.0", "4.5.1", "4.5.2", "4.5.3", "4.5.4", "4.5.5", "4.5.6", "4.5.7", "4.5.8", "4.5.9", "4.5.10", "4.6.0", "4.6.1", "4.6.2", "4.6.3", "4.6.4", "4.6.5", "4.6.6", "4.6.7", "4.6.8", "4.7.0", "4.7.1", "4.7.2", "4.7.3", "4.7.4", "4.7.5-pre", "4.7.5", "4.7.6", "4.7.7", "4.7.8", "4.7.9", "4.8.0", "4.8.1", "4.8.2", "4.8.3", "4.8.4", "4.8.5", "4.8.6", "4.8.7", "4.9.0", "4.9.1", "4.9.2", "4.9.3", "4.9.4", "4.9.5", "4.9.6", "4.9.7", "4.9.8", "4.9.9", "4.9.10", "4.10.0", "4.10.1", "4.10.2", "4.10.3", "4.10.4", "4.10.5", "4.10.6", "4.10.7", "4.10.8", "4.11.0", "4.11.1", "4.11.2", "4.11.3", "4.11.4", "4.11.5", "4.11.6", "4.11.7", "4.11.8", "4.11.9", "4.11.10", "4.11.11", "4.11.12", "4.11.13", "4.11.14", "4.12.0", "4.12.1", "4.12.2", "4.12.3", "4.12.4", "4.12.5", "4.12.6", "4.13.0", "4.13.1", "4.13.2", "4.13.3", "4.13.4", "4.13.5", "4.13.6", "4.13.7", "4.13.8", "5.0.0-rc0", "5.0.0-rc1", "5.0.0-rc2", "4.13.9", "5.0.0", "5.0.1", "4.13.10", "5.0.2", "5.0.3", "4.13.11", "5.0.4", "5.0.5", "5.0.6", "5.0.7", "5.0.8", "5.0.9", "5.0.10", "4.13.12", "5.0.11", "5.0.12", "5.0.13", "5.0.14", "5.0.15", "5.0.16", "5.0.17", "5.0.18", "5.1.0", "5.1.1", "4.13.13", "5.1.2", "4.13.14", "5.1.3", "5.1.4", "5.1.5", "5.1.6", "5.1.7", "5.1.8", "5.2.0", "5.2.1", "5.2.2", "5.2.3", "5.2.4", "5.2.5", "5.2.6", "5.2.7", "5.2.8", "4.13.15", "5.2.9", "5.2.10", "4.13.16", "5.2.11", "4.13.17", "5.2.12", "5.2.13", "5.2.14", "5.2.15", "5.2.16", "5.2.17", "5.2.18", "5.3.0", "5.3.1", "5.3.2", "5.3.3", "5.3.4", "5.3.5", "5.3.6", "5.3.7", "5.3.8", "5.3.9", "5.3.10", "5.3.11", "5.3.12", "5.3.13", "5.3.14", "5.3.15", "5.3.16", "5.4.0", "5.4.1", "5.4.2", "5.4.3", "5.4.4", "5.4.5", "4.13.18", "5.4.6", "5.4.7", "5.4.8", "5.4.9", "5.4.10", "5.4.11", "5.4.12", "5.4.13", "5.4.14", "5.4.15", "5.4.16", "5.4.17", "5.4.18", "5.4.19", "5.4.20", "5.4.21", "5.4.22", "5.4.23", "5.5.0", "5.5.1", "5.5.2", "5.5.3", "5.5.4", "5.5.5", "5.5.6", "5.5.7", "5.5.8", "5.5.9", "5.5.10", "5.5.11", "5.5.12", "5.5.13", "5.5.14", "5.5.15", "5.6.0", "5.6.1", "5.6.2", "5.6.3", "5.6.4", "5.6.5", "4.13.19", "5.6.6", "5.6.7", "5.6.8", "5.6.9", "5.6.10", "5.6.11", "5.6.12", "5.6.13", "5.7.0", "5.7.1", "5.7.3", "5.7.4", "5.7.5", "5.7.6", "5.7.7", "5.7.8", "5.7.9", "5.7.10", "5.7.11", "5.7.12", "5.7.13", "5.7.14", "5.8.0", "5.8.1", "5.8.2", "5.8.3", "5.8.4", "5.8.5", "4.13.20", "5.8.6", "5.8.7", "5.8.9", "5.8.10", "5.8.11", "5.8.12", "5.8.13", "5.9.0", "5.9.1", "5.9.2", "5.9.3", "5.9.4", "5.9.5", "5.9.6", "5.9.7", "5.9.9", "5.9.10", "5.9.11", "5.9.12", "5.9.13", "5.9.14", "5.9.15", "5.9.16", "5.9.17", "5.9.18", "5.9.19", "5.9.20", "5.9.21", "5.9.22", "5.9.23", "4.13.21", "5.9.24", "5.9.25", "5.9.26", "5.9.27", "5.9.28", "5.9.29", "5.10.0", "5.10.1", "5.10.2", "5.10.3", "5.10.4", "5.10.5", "5.10.6", "5.10.7", "5.10.8", "5.10.9", "5.10.10", "5.10.11", "5.10.12", "5.10.13", "5.10.14", "5.10.15", "5.10.16", "5.10.17", "5.10.18", "5.10.19", "5.11.0", "5.11.1", "5.11.2", "5.11.3", "5.11.4", "5.11.5", "5.11.6", "5.11.7", "5.11.8", "5.11.9", "5.11.10", "5.11.11", "5.11.12", "5.11.13", "5.11.14", "5.11.15", "5.11.16", "5.11.17", "5.11.18", "5.11.19", "5.11.20", "5.12.0", "5.12.1", "5.12.2", "5.12.3", "5.12.4", "5.12.5", "5.12.6", "5.12.7", "5.12.8", "5.12.9", "5.12.10", "5.12.11", "5.12.12", "5.12.13", "5.12.14", "5.12.15", "5.13.0", "5.13.1", "5.13.2", "5.13.3", "5.13.4", "5.13.5", "5.13.6", "5.13.7", "5.13.8", "5.13.9", "5.13.10", "5.13.11", "5.13.12", "5.13.13", "5.13.14", "6.0.0", "6.0.1", "6.0.2", "6.0.3", "6.0.4", "6.0.5", "6.0.6", "6.0.7", "6.0.8", "6.0.9", "6.0.10", "6.0.11", "6.0.12", "6.0.13", "6.0.14", "6.0.15", "6.1.0", "6.1.1", "6.1.2", "6.1.3", "6.1.4", "6.1.5", "6.1.6", "6.1.7", "6.1.8", "6.1.9", "6.1.10", "6.2.0", "6.2.1", "6.2.2", "6.2.3", "6.2.4", "6.2.5", "6.2.6", "6.2.7", "6.2.8", "6.2.9", "6.2.10", "6.2.11", "6.3.0", "6.3.1", "6.3.2", "6.3.3", "6.3.4", "6.3.5", "6.3.6", "6.3.7", "6.3.8", "6.3.9", "6.4.0", "6.4.1", "6.4.2", "6.4.3", "6.4.4", "6.4.5"]
Secure versions: [6.0.0-rc0, 6.0.0-rc1, 6.0.0-rc2, 7.0.0-rc0, 7.3.3, 6.11.3, 5.13.20, 7.3.4, 6.11.4, 7.4.0, 7.4.1, 6.11.5, 7.4.2, 7.4.3, 6.11.6, 7.4.4, 6.12.0, 7.4.5, 7.5.0, 7.5.1, 7.5.2, 7.5.3, 7.5.4, 7.6.0, 7.6.1, 6.12.1, 7.6.2, 7.6.3, 5.13.21, 8.0.0-rc0, 6.12.2, 7.6.4, 8.0.0, 6.12.3, 7.6.5, 8.0.1, 7.6.6, 8.0.2, 7.6.7, 8.0.3, 6.12.4, 5.13.22, 6.12.5, 7.6.8, 8.0.4, 8.1.0, 6.12.6, 8.1.1, 8.1.2, 8.1.3, 8.2.0, 7.6.9, 6.12.7, 8.2.1, 7.6.10, 8.2.2, 8.2.3, 8.2.4, 8.3.0, 8.3.1, 6.12.8, 7.6.11, 8.3.2, 8.3.3, 8.3.4, 8.3.5, 8.4.0, 7.6.12, 6.12.9, 8.4.1, 7.6.13, 6.13.0, 8.4.2, 8.4.3, 7.7.0, 8.4.4, 8.4.5, 8.5.0, 8.5.1, 7.8.0, 8.5.2, 8.5.3, 7.8.1, 8.5.4, 8.5.5, 8.6.0, 8.6.1, 6.13.1, 8.6.2, 6.13.2, 8.6.3, 6.13.3, 7.8.2, 8.6.4, 8.7.0, 8.7.1, 8.7.2, 8.7.3, 8.8.0, 8.8.1]
Recommendation: Update to version 8.8.1.

Remote Memory Exposure

Published date: 2016-01-15
CVSS Score: 6.5
CVSS Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H
Links:

Trying to save a number to a field of type Buffer on the affected mongoose versions allocates a chunk of uninitialized memory and stores it in the database.

Affected versions: ["3.5.5", "3.5.6", "3.5.7", "3.5.8", "3.5.9", "3.6.2", "3.5.10", "3.6.3", "3.5.11", "3.6.4", "3.6.5", "3.6.6", "3.6.7", "3.5.12", "3.6.8", "3.6.9", "3.6.10", "3.5.13", "3.5.14", "3.6.11", "3.6.12", "3.6.13", "3.6.14", "3.6.15", "3.5.15", "3.7.0", "3.6.16", "3.5.16", "3.6.17", "3.7.2", "3.6.0-rc0", "3.6.0-rc1", "3.6.18", "3.7.3", "3.6.19", "3.6.20", "3.7.4", "3.8.0", "3.8.1", "3.8.2", "3.8.3", "3.8.4", "3.8.5", "3.8.6", "3.8.7", "3.8.8", "3.8.9", "3.8.10", "3.8.11", "3.8.12", "3.8.13", "3.8.14", "3.8.15", "3.8.16", "3.8.17", "3.8.18", "3.8.19", "3.8.20", "3.8.21", "3.8.22", "3.8.23", "3.8.24", "3.8.25", "3.8.26", "3.8.27", "3.8.28", "3.8.29", "3.8.30", "3.8.31", "3.8.33", "3.8.34", "3.8.35", "3.8.36", "3.8.37", "3.8.38", "4.0.0", "4.0.1", "4.0.2", "4.0.3", "4.0.4", "4.0.5", "4.0.6", "4.0.7", "4.0.8", "4.1.0", "4.1.1", "4.1.2", "4.1.3", "4.1.5", "4.1.6", "4.1.7", "4.1.8", "4.1.9", "4.1.10", "4.1.11", "4.1.12", "4.2.0", "4.2.1", "4.2.2", "4.2.3", "4.2.4", "4.2.5", "4.2.6", "4.2.7", "4.2.8", "4.2.9", "4.2.10", "4.3.0", "4.3.1", "4.3.2", "4.3.3", "4.3.4", "4.3.5", "0.0.1", "0.0.2", "0.0.3", "0.0.4", "0.0.5", "1.0.0", "1.0.1", "1.0.2", "0.0.6", "1.0.3", "1.0.4", "1.0.5", "1.0.6", "1.0.7", "1.0.8", "1.0.10", "1.0.11", "1.0.12", "1.0.13", "1.0.14", "1.0.15", "1.0.16", "1.1.0", "1.1.1", "1.1.2", "1.1.3", "1.1.4", "1.1.5", "1.1.6", "1.1.7", "1.1.8", "1.1.9", "1.1.10", "1.1.11", "1.1.12", "1.1.13", "1.1.14", "1.1.15", "1.1.16", "1.1.17", "1.1.18", "1.1.19", "1.1.20", "1.1.21", "1.1.22", "1.1.23", "1.1.24", "1.1.25", "1.2.0", "1.3.0", "1.3.1", "1.3.2", "1.3.3", "1.3.4", "1.3.5", "1.3.6", "1.3.7", "1.4.0", "1.5.0", "1.6.0", "1.7.2", "1.7.3", "1.7.4", "1.8.0", "1.8.1", "1.8.2", "1.8.3", "1.8.4", "2.0.0", "2.0.1", "2.0.2", "2.0.3", "2.0.4", "2.1.0", "2.1.1", "2.1.2", "2.1.3", "2.1.4", "2.2.0", "2.2.1", "2.2.2", "2.2.3", "2.2.4", "2.3.0", "2.3.1", "2.3.2", "2.3.3", "2.3.4", "2.3.5", "2.3.6", "2.3.7", "2.3.8", "2.3.9", "2.3.10", "2.3.11", "2.3.12", "2.3.13", "2.4.0", "2.4.1", "2.4.2", "2.4.3", "2.4.4", "2.4.5", "2.4.6", "2.4.7", "2.4.8", "2.4.9", "2.4.10", "2.5.0", "2.5.1", "2.5.2", "2.5.3", "2.5.4", "2.5.5", "2.5.6", "2.5.7", "2.5.8", "2.5.9", "2.5.10", "2.5.11", "2.5.12", "2.5.13", "2.5.14", "2.6.0", "2.6.1", "2.6.2", "2.6.3", "2.6.4", "2.6.5", "2.6.6", "2.6.7", "2.6.8", "2.7.0", "2.7.1", "2.7.2", "2.7.4", "2.7.3", "3.0.0", "3.0.1", "3.0.2", "2.8.0", "3.0.3", "3.1.0", "2.8.1", "3.1.1", "2.8.2", "2.8.3", "2.9.0", "3.2.0", "2.9.1", "3.2.1", "2.9.2", "3.2.2", "3.3.0", "3.3.1", "2.9.3", "3.4.0", "2.9.4", "2.9.5", "3.5.0", "3.5.1", "3.5.2", "3.5.3", "2.9.6", "2.9.7", "3.5.4", "2.9.8", "2.9.9", "2.9.10", "3.0.0-alpha1", "3.0.0-alpha2", "3.0.0-rc0"]
Secure versions: [6.0.0-rc0, 6.0.0-rc1, 6.0.0-rc2, 7.0.0-rc0, 7.3.3, 6.11.3, 5.13.20, 7.3.4, 6.11.4, 7.4.0, 7.4.1, 6.11.5, 7.4.2, 7.4.3, 6.11.6, 7.4.4, 6.12.0, 7.4.5, 7.5.0, 7.5.1, 7.5.2, 7.5.3, 7.5.4, 7.6.0, 7.6.1, 6.12.1, 7.6.2, 7.6.3, 5.13.21, 8.0.0-rc0, 6.12.2, 7.6.4, 8.0.0, 6.12.3, 7.6.5, 8.0.1, 7.6.6, 8.0.2, 7.6.7, 8.0.3, 6.12.4, 5.13.22, 6.12.5, 7.6.8, 8.0.4, 8.1.0, 6.12.6, 8.1.1, 8.1.2, 8.1.3, 8.2.0, 7.6.9, 6.12.7, 8.2.1, 7.6.10, 8.2.2, 8.2.3, 8.2.4, 8.3.0, 8.3.1, 6.12.8, 7.6.11, 8.3.2, 8.3.3, 8.3.4, 8.3.5, 8.4.0, 7.6.12, 6.12.9, 8.4.1, 7.6.13, 6.13.0, 8.4.2, 8.4.3, 7.7.0, 8.4.4, 8.4.5, 8.5.0, 8.5.1, 7.8.0, 8.5.2, 8.5.3, 7.8.1, 8.5.4, 8.5.5, 8.6.0, 8.6.1, 6.13.1, 8.6.2, 6.13.2, 8.6.3, 6.13.3, 7.8.2, 8.6.4, 8.7.0, 8.7.1, 8.7.2, 8.7.3, 8.8.0, 8.8.1]
Recommendation: update mongoose to 4.3.6 or higher

892 Other Versions

Version License Security Released
5.3.15 MIT 4 2018-12-05 - 22:24 almost 6 years
5.3.14 MIT 4 2018-11-27 - 15:52 almost 6 years
5.3.13 MIT 4 2018-11-20 - 15:26 almost 6 years
5.3.12 MIT 4 2018-11-13 - 15:06 almost 6 years
5.3.11 MIT 4 2018-11-09 - 23:18 about 6 years
5.3.10 MIT 4 2018-11-06 - 22:37 about 6 years
5.3.9 MIT 4 2018-11-02 - 21:46 about 6 years
5.3.8 MIT 4 2018-10-30 - 21:25 about 6 years
5.3.7 MIT 4 2018-10-26 - 13:19 about 6 years
5.3.6 MIT 4 2018-10-23 - 14:15 about 6 years
5.3.5 MIT 4 2018-10-22 - 13:23 about 6 years
5.3.4 MIT 4 2018-10-15 - 17:20 about 6 years
5.3.3 MIT 4 2018-10-12 - 16:30 about 6 years
5.3.2 MIT 4 2018-10-07 - 21:45 about 6 years
5.3.1 MIT 4 2018-10-02 - 13:00 about 6 years
5.3.0 MIT 4 2018-09-28 - 21:25 about 6 years
5.2.18 MIT 4 2018-09-27 - 22:32 about 6 years
5.2.17 MIT 4 2018-09-21 - 18:04 about 6 years
5.2.16 MIT 4 2018-09-19 - 21:46 about 6 years
5.2.15 MIT 4 2018-09-15 - 20:50 about 6 years
5.2.14 MIT 4 2018-09-10 - 00:23 about 6 years
5.2.13 MIT 4 2018-09-04 - 12:49 about 6 years
5.2.12 MIT 4 2018-08-30 - 17:00 about 6 years
5.2.11 MIT 4 2018-08-30 - 15:28 about 6 years
5.2.10 MIT 4 2018-08-27 - 13:12 about 6 years
5.2.9 MIT 4 2018-08-17 - 13:10 about 6 years
5.2.8 MIT 4 2018-08-14 - 01:30 about 6 years
5.2.7 MIT 4 2018-08-06 - 16:09 over 6 years
5.2.6 MIT 4 2018-07-30 - 23:51 over 6 years
5.2.5 MIT 4 2018-07-23 - 20:08 over 6 years
5.2.4 MIT 4 2018-07-16 - 18:58 over 6 years
5.2.3 MIT 4 2018-07-11 - 14:37 over 6 years
5.2.2 MIT 4 2018-07-08 - 23:59 over 6 years
5.2.1 MIT 4 2018-07-04 - 02:42 over 6 years
5.2.0 MIT 4 2018-07-03 - 00:46 over 6 years
5.1.8 MIT 4 2018-07-02 - 20:07 over 6 years
5.1.7 MIT 4 2018-06-26 - 19:31 over 6 years
5.1.6 MIT 4 2018-06-19 - 15:11 over 6 years
5.1.5 MIT 4 2018-06-11 - 20:51 over 6 years
5.1.4 MIT 4 2018-06-04 - 16:09 over 6 years
5.1.3 MIT 4 2018-05-29 - 00:06 over 6 years
5.1.2 MIT 4 2018-05-21 - 20:19 over 6 years
5.1.1 MIT 4 2018-05-14 - 20:02 over 6 years
5.1.0 MIT 4 2018-05-10 - 20:42 over 6 years
5.0.18 MIT 4 2018-05-09 - 21:24 over 6 years
5.0.17 MIT 4 2018-04-30 - 21:04 over 6 years
5.0.16 MIT 4 2018-04-23 - 16:30 over 6 years
5.0.15 MIT 4 2018-04-16 - 19:01 over 6 years
5.0.14 MIT 4 2018-04-09 - 16:11 over 6 years
5.0.13 MIT 4 2018-04-05 - 10:36 over 6 years
5.0.12 MIT 4 2018-03-27 - 15:05 over 6 years
5.0.11 MIT 4 2018-03-19 - 19:52 over 6 years
5.0.10 MIT 4 2018-03-13 - 00:03 over 6 years
5.0.9 MIT 4 2018-03-05 - 22:16 over 6 years
5.0.8 MIT 4 2018-03-03 - 16:11 over 6 years
5.0.7 MIT 4 2018-02-23 - 17:24 over 6 years
5.0.6 MIT 4 2018-02-15 - 23:52 over 6 years
5.0.5 MIT 4 2018-02-13 - 20:46 over 6 years
5.0.4 MIT 4 2018-02-08 - 21:34 almost 7 years
5.0.3 MIT 4 2018-02-01 - 04:35 almost 7 years
5.0.2 MIT 4 2018-01-28 - 23:30 almost 7 years
5.0.1 MIT 4 2018-01-20 - 02:58 almost 7 years
5.0.0 MIT 4 2018-01-17 - 22:36 almost 7 years
5.0.0-rc2 MIT 3 2018-01-04 - 18:03 almost 7 years
5.0.0-rc1 MIT 3 2018-01-02 - 15:59 almost 7 years
5.0.0-rc0 MIT 3 2017-12-28 - 17:14 almost 7 years
4.13.21 MIT 3 2020-07-12 - 17:56 over 4 years
4.13.20 MIT 4 2020-01-08 - 03:36 almost 5 years
4.13.19 MIT 4 2019-07-17 - 17:54 over 5 years
4.13.18 MIT 4 2019-01-22 - 04:12 almost 6 years
4.13.17 MIT 4 2018-08-30 - 16:46 about 6 years
4.13.16 MIT 4 2018-08-30 - 14:58 about 6 years
4.13.15 MIT 4 2018-08-14 - 15:11 about 6 years
4.13.14 MIT 4 2018-05-25 - 15:44 over 6 years
4.13.13 MIT 4 2018-05-17 - 19:09 over 6 years
4.13.12 MIT 4 2018-03-14 - 04:53 over 6 years
4.13.11 MIT 4 2018-02-08 - 03:49 almost 7 years
4.13.10 MIT 4 2018-01-28 - 16:19 almost 7 years
4.13.9 MIT 4 2018-01-07 - 18:48 almost 7 years
4.13.8 MIT 4 2017-12-27 - 17:54 almost 7 years
4.13.7 MIT 4 2017-12-12 - 02:01 almost 7 years
4.13.6 MIT 4 2017-12-02 - 23:45 almost 7 years
4.13.5 MIT 4 2017-11-24 - 18:06 almost 7 years
4.13.4 MIT 4 2017-11-17 - 18:29 almost 7 years
4.13.3 MIT 4 2017-11-16 - 06:14 almost 7 years
4.13.2 MIT 4 2017-11-13 - 06:24 almost 7 years
4.13.1 MIT 4 2017-11-09 - 01:32 about 7 years
4.13.0 MIT 4 2017-11-03 - 00:30 about 7 years
4.12.6 MIT 4 2017-11-01 - 15:55 about 7 years
4.12.5 MIT 4 2017-10-30 - 05:40 about 7 years
4.12.4 MIT 4 2017-10-21 - 23:15 about 7 years
4.12.3 MIT 4 2017-10-16 - 16:11 about 7 years
4.12.2 MIT 4 2017-10-14 - 15:01 about 7 years
4.12.1 MIT 4 2017-10-08 - 17:23 about 7 years
4.12.0 MIT 4 2017-10-03 - 03:32 about 7 years
4.11.14 MIT 4 2017-09-30 - 21:22 about 7 years
4.11.13 MIT 4 2017-09-25 - 04:23 about 7 years
4.11.12 MIT 4 2017-09-18 - 17:23 about 7 years
4.11.11 MIT 4 2017-09-10 - 18:54 about 7 years
4.11.10 MIT 4 2017-09-04 - 03:32 about 7 years