NodeJS/mongoose/2.9.8


Mongoose MongoDB ODM

https://www.npmjs.com/package/mongoose
MIT

5 Security Vulnerabilities

Improper Input Validation in Automattic Mongoose

Published date: 2019-10-22T20:19:54Z
CVE: CVE-2019-17426
Links:

Automattic Mongoose through 5.7.4 allows attackers to bypass access control (in some applications) because any query object with a _bsontype attribute is ignored. For example, adding "_bsontype":"a" can sometimes interfere with a query filter. NOTE: this CVE is about Mongoose's failure to work around this _bsontype special case that exists in older versions of the bson parser (aka the mongodb/js-bson project).

Affected versions: ["0.0.1", "0.0.2", "0.0.3", "0.0.4", "0.0.5", "1.0.0", "1.0.1", "1.0.2", "0.0.6", "1.0.3", "1.0.4", "1.0.5", "1.0.6", "1.0.7", "1.0.8", "1.0.10", "1.0.11", "1.0.12", "1.0.13", "1.0.14", "1.0.15", "1.0.16", "1.1.0", "1.1.1", "1.1.2", "1.1.3", "1.1.4", "1.1.5", "1.1.6", "1.1.7", "1.1.8", "1.1.9", "1.1.10", "1.1.11", "1.1.12", "1.1.13", "1.1.14", "1.1.15", "1.1.16", "1.1.17", "1.1.18", "1.1.19", "1.1.20", "1.1.21", "1.1.22", "1.1.23", "1.1.24", "1.1.25", "1.2.0", "1.3.0", "1.3.1", "1.3.2", "1.3.3", "1.3.4", "1.3.5", "1.3.6", "1.3.7", "1.4.0", "1.5.0", "1.6.0", "1.7.2", "1.7.3", "1.7.4", "1.8.0", "1.8.1", "1.8.2", "1.8.3", "1.8.4", "2.0.0", "2.0.1", "2.0.2", "2.0.3", "2.0.4", "2.1.0", "2.1.1", "2.1.2", "2.1.3", "2.1.4", "2.2.0", "2.2.1", "2.2.2", "2.2.3", "2.2.4", "2.3.0", "2.3.1", "2.3.2", "2.3.3", "2.3.4", "2.3.5", "2.3.6", "2.3.7", "2.3.8", "2.3.9", "2.3.10", "2.3.11", "2.3.12", "2.3.13", "2.4.0", "2.4.1", "2.4.2", "2.4.3", "2.4.4", "2.4.5", "2.4.6", "2.4.7", "2.4.8", "2.4.9", "2.4.10", "2.5.0", "2.5.1", "2.5.2", "2.5.3", "2.5.4", "2.5.5", "2.5.6", "2.5.7", "2.5.8", "2.5.9", "2.5.10", "2.5.11", "2.5.12", "2.5.13", "2.5.14", "2.6.0", "2.6.1", "2.6.2", "2.6.3", "2.6.4", "2.6.5", "2.6.6", "2.6.7", "2.6.8", "2.7.0", "2.7.1", "2.7.2", "2.7.4", "2.7.3", "3.0.0", "3.0.1", "3.0.2", "2.8.0", "3.0.3", "3.1.0", "2.8.1", "3.1.1", "2.8.2", "2.8.3", "2.9.0", "3.2.0", "2.9.1", "3.2.1", "2.9.2", "3.2.2", "3.3.0", "3.3.1", "2.9.3", "3.4.0", "2.9.4", "2.9.5", "3.5.0", "3.5.1", "3.5.2", "3.5.3", "2.9.6", "2.9.7", "3.5.4", "3.5.5", "2.9.8", "2.9.9", "3.5.6", "3.5.7", "3.5.8", "2.9.10", "3.5.9", "3.6.2", "3.5.10", "3.6.3", "3.5.11", "3.6.4", "3.6.5", "3.6.6", "3.6.7", "3.5.12", "3.6.8", "3.6.9", "3.6.10", "3.5.13", "3.5.14", "3.6.11", "3.6.12", "3.6.13", "3.6.14", "3.6.15", "3.5.15", "3.7.0", "3.6.16", "3.5.16", "3.6.17", "3.7.2", "3.0.0-alpha1", "3.0.0-alpha2", "3.0.0-rc0", "3.6.0-rc0", "3.6.0-rc1", "3.6.18", "3.7.3", "3.6.19", "3.6.20", "3.7.4", "3.8.0", "3.8.1", "3.8.2", "3.8.3", "3.8.4", "3.8.5", "3.8.6", "3.8.7", "3.8.8", "3.8.9", "3.8.10", "3.8.11", "3.9.0", "3.8.12", "3.8.13", "3.8.14", "3.8.15", "3.9.1", "3.8.16", "3.9.2", "3.8.17", "3.9.3", "3.8.18", "3.9.4", "3.8.19", "3.9.5", "3.8.20", "3.9.6", "3.8.21", "3.9.7", "3.8.22", "4.0.0-rc0", "4.0.0-rc1", "3.8.23", "4.0.0-rc2", "3.8.24", "4.0.0-rc3", "3.8.25", "4.0.0-rc4", "4.0.0", "4.0.1", "3.8.26", "3.8.27", "4.0.2", "3.8.28", "4.0.3", "3.8.29", "4.0.4", "3.8.30", "4.0.5", "3.8.31", "4.0.6", "3.8.33", "4.0.7", "3.8.34", "4.0.8", "4.1.0", "4.1.1", "4.1.2", "3.8.35", "4.1.3", "4.1.5", "4.1.6", "4.1.7", "4.1.8", "4.1.9", "4.1.10", "4.1.11", "3.8.36", "4.1.12", "4.2.0", "4.2.1", "4.2.2", "4.2.3", "4.2.4", "4.2.5", "3.8.37", "4.2.6", "4.2.7", "4.2.8", "4.2.9", "4.2.10", "4.3.0", "4.3.1", "4.3.2", "4.3.3", "4.3.4", "3.8.38", "4.3.5", "4.3.6", "3.8.39", "4.3.7", "4.4.0", "4.4.1", "4.4.2", "4.4.3", "4.4.4", "4.4.5", "4.4.6", "4.4.7", "4.4.8", "4.4.9", "4.4.10", "4.4.11", "4.4.12", "4.4.13", "3.8.40", "4.4.14", "4.4.15", "4.4.16", "4.4.17", "4.4.18", "4.4.19", "4.4.20", "4.5.0", "4.5.1", "4.5.2", "4.5.3", "4.5.4", "4.5.5", "4.5.6", "4.5.7", "4.5.8", "4.5.9", "4.5.10", "4.6.0", "4.6.1", "4.6.2", "4.6.3", "4.6.4", "4.6.5", "4.6.6", "4.6.7", "4.6.8", "4.7.0", "4.7.1", "4.7.2", "4.7.3", "4.7.4", "4.7.5-pre", "4.7.5", "4.7.6", "4.7.7", "4.7.8", "4.7.9", "4.8.0", "4.8.1", "4.8.2", "4.8.3", "4.8.4", "4.8.5", "4.8.6", "4.8.7", "4.9.0", "4.9.1", "4.9.2", "4.9.3", "4.9.4", "4.9.5", "4.9.6", "4.9.7", "4.9.8", "4.9.9", "4.9.10", "4.10.0", "4.10.1", "4.10.2", "4.10.3", "4.10.4", "4.10.5", "4.10.6", "4.10.7", "4.10.8", "4.11.0", "4.11.1", "4.11.2", "4.11.3", "4.11.4", "4.11.5", "4.11.6", "4.11.7", "4.11.8", "4.11.9", "4.11.10", "4.11.11", "4.11.12", "4.11.13", "4.11.14", "4.12.0", "4.12.1", "4.12.2", "4.12.3", "4.12.4", "4.12.5", "4.12.6", "4.13.0", "4.13.1", "4.13.2", "4.13.3", "4.13.4", "4.13.5", "4.13.6", "4.13.7", "4.13.8", "4.13.9", "4.13.10", "4.13.11", "4.13.12", "4.13.13", "4.13.14", "4.13.15", "4.13.16", "4.13.17", "4.13.18", "4.13.19", "4.13.20", "5.0.0", "5.0.1", "5.0.2", "5.0.3", "5.0.4", "5.0.5", "5.0.6", "5.0.7", "5.0.8", "5.0.9", "5.0.10", "5.0.11", "5.0.12", "5.0.13", "5.0.14", "5.0.15", "5.0.16", "5.0.17", "5.0.18", "5.1.0", "5.1.1", "5.1.2", "5.1.3", "5.1.4", "5.1.5", "5.1.6", "5.1.7", "5.1.8", "5.2.0", "5.2.1", "5.2.2", "5.2.3", "5.2.4", "5.2.5", "5.2.6", "5.2.7", "5.2.8", "5.2.9", "5.2.10", "5.2.11", "5.2.12", "5.2.13", "5.2.14", "5.2.15", "5.2.16", "5.2.17", "5.2.18", "5.3.0", "5.3.1", "5.3.2", "5.3.3", "5.3.4", "5.3.5", "5.3.6", "5.3.7", "5.3.8", "5.3.9", "5.3.10", "5.3.11", "5.3.12", "5.3.13", "5.3.14", "5.3.15", "5.3.16", "5.4.0", "5.4.1", "5.4.2", "5.4.3", "5.4.4", "5.4.5", "5.4.6", "5.4.7", "5.4.8", "5.4.9", "5.4.10", "5.4.11", "5.4.12", "5.4.13", "5.4.14", "5.4.15", "5.4.16", "5.4.17", "5.4.18", "5.4.19", "5.4.20", "5.4.21", "5.4.22", "5.4.23", "5.5.0", "5.5.1", "5.5.2", "5.5.3", "5.5.4", "5.5.5", "5.5.6", "5.5.7", "5.5.8", "5.5.9", "5.5.10", "5.5.11", "5.5.12", "5.5.13", "5.5.14", "5.5.15", "5.6.0", "5.6.1", "5.6.2", "5.6.3", "5.6.4", "5.6.5", "5.6.6", "5.6.7", "5.6.8", "5.6.9", "5.6.10", "5.6.11", "5.6.12", "5.6.13", "5.7.0", "5.7.1", "5.7.3", "5.7.4"]
Secure versions: [6.0.0-rc0, 6.0.0-rc1, 6.0.0-rc2, 7.0.0-rc0, 7.3.3, 6.11.3, 5.13.20, 7.3.4, 6.11.4, 7.4.0, 7.4.1, 6.11.5, 7.4.2, 7.4.3, 6.11.6, 7.4.4, 6.12.0, 7.4.5, 7.5.0, 7.5.1, 7.5.2, 7.5.3, 7.5.4, 7.6.0, 7.6.1, 6.12.1, 7.6.2, 7.6.3, 5.13.21, 8.0.0-rc0, 6.12.2, 7.6.4, 8.0.0, 6.12.3, 7.6.5, 8.0.1, 7.6.6, 8.0.2, 7.6.7, 8.0.3, 6.12.4, 5.13.22, 6.12.5, 7.6.8, 8.0.4, 8.1.0, 6.12.6, 8.1.1, 8.1.2, 8.1.3, 8.2.0, 7.6.9, 6.12.7, 8.2.1, 7.6.10, 8.2.2, 8.2.3, 8.2.4, 8.3.0, 8.3.1, 6.12.8, 7.6.11, 8.3.2, 8.3.3, 8.3.4, 8.3.5, 8.4.0, 7.6.12, 6.12.9, 8.4.1, 7.6.13, 6.13.0, 8.4.2, 8.4.3, 7.7.0, 8.4.4, 8.4.5, 8.5.0, 8.5.1, 7.8.0, 8.5.2, 8.5.3, 7.8.1, 8.5.4, 8.5.5, 8.6.0, 8.6.1, 6.13.1, 8.6.2, 6.13.2, 8.6.3, 6.13.3, 7.8.2, 8.6.4, 8.7.0, 8.7.1, 8.7.2, 8.7.3]
Recommendation: Update to version 8.7.3.

Mongoose Prototype Pollution vulnerability

Published date: 2023-07-17T03:30:20Z
CVE: CVE-2023-3696
Links:

Prototype Pollution in GitHub repository automattic/mongoose prior to 7.3.3, 6.11.3, and 5.13.20.

Affected versions: ["0.0.1", "0.0.2", "0.0.3", "0.0.4", "0.0.5", "1.0.0", "1.0.1", "1.0.2", "0.0.6", "1.0.3", "1.0.4", "1.0.5", "1.0.6", "1.0.7", "1.0.8", "1.0.10", "1.0.11", "1.0.12", "1.0.13", "1.0.14", "1.0.15", "1.0.16", "1.1.0", "1.1.1", "1.1.2", "1.1.3", "1.1.4", "1.1.5", "1.1.6", "1.1.7", "1.1.8", "1.1.9", "1.1.10", "1.1.11", "1.1.12", "1.1.13", "1.1.14", "1.1.15", "1.1.16", "1.1.17", "1.1.18", "1.1.19", "1.1.20", "1.1.21", "1.1.22", "1.1.23", "1.1.24", "1.1.25", "1.2.0", "1.3.0", "1.3.1", "1.3.2", "1.3.3", "1.3.4", "1.3.5", "1.3.6", "1.3.7", "1.4.0", "1.5.0", "1.6.0", "1.7.2", "1.7.3", "1.7.4", "1.8.0", "1.8.1", "1.8.2", "1.8.3", "1.8.4", "2.0.0", "2.0.1", "2.0.2", "2.0.3", "2.0.4", "2.1.0", "2.1.1", "2.1.2", "2.1.3", "2.1.4", "2.2.0", "2.2.1", "2.2.2", "2.2.3", "2.2.4", "2.3.0", "2.3.1", "2.3.2", "2.3.3", "2.3.4", "2.3.5", "2.3.6", "2.3.7", "2.3.8", "2.3.9", "2.3.10", "2.3.11", "2.3.12", "2.3.13", "2.4.0", "2.4.1", "2.4.2", "2.4.3", "2.4.4", "2.4.5", "2.4.6", "2.4.7", "2.4.8", "2.4.9", "2.4.10", "2.5.0", "2.5.1", "2.5.2", "2.5.3", "2.5.4", "2.5.5", "2.5.6", "2.5.7", "2.5.8", "2.5.9", "2.5.10", "2.5.11", "2.5.12", "2.5.13", "2.5.14", "2.6.0", "2.6.1", "2.6.2", "2.6.3", "2.6.4", "2.6.5", "2.6.6", "2.6.7", "2.6.8", "2.7.0", "2.7.1", "2.7.2", "2.7.4", "2.7.3", "3.0.0", "3.0.1", "3.0.2", "2.8.0", "3.0.3", "3.1.0", "2.8.1", "3.1.1", "2.8.2", "2.8.3", "2.9.0", "3.2.0", "2.9.1", "3.2.1", "2.9.2", "3.2.2", "3.3.0", "3.3.1", "2.9.3", "3.4.0", "2.9.4", "2.9.5", "3.5.0", "3.5.1", "3.5.2", "3.5.3", "2.9.6", "2.9.7", "3.5.4", "3.5.5", "2.9.8", "2.9.9", "3.5.6", "3.5.7", "3.5.8", "2.9.10", "3.5.9", "3.6.2", "3.5.10", "3.6.3", "3.5.11", "3.6.4", "3.6.5", "3.6.6", "3.6.7", "3.5.12", "3.6.8", "3.6.9", "3.6.10", "3.5.13", "3.5.14", "3.6.11", "3.6.12", "3.6.13", "3.6.14", "3.6.15", "3.5.15", "3.7.0", "3.6.16", "3.5.16", "3.6.17", "3.7.2", "3.0.0-alpha1", "3.0.0-alpha2", "3.0.0-rc0", "3.6.0-rc0", "3.6.0-rc1", "3.6.18", "3.7.3", "3.6.19", "3.6.20", "3.7.4", "3.8.0", "3.8.1", "3.8.2", "3.8.3", "3.8.4", "3.8.5", "3.8.6", "3.8.7", "3.8.8", "3.8.9", "3.8.10", "3.8.11", "3.9.0", "3.8.12", "3.8.13", "3.8.14", "3.8.15", "3.9.1", "3.8.16", "3.9.2", "3.8.17", "3.9.3", "3.8.18", "3.9.4", "3.8.19", "3.9.5", "3.8.20", "3.9.6", "3.8.21", "3.9.7", "3.8.22", "4.0.0-rc0", "4.0.0-rc1", "3.8.23", "4.0.0-rc2", "3.8.24", "4.0.0-rc3", "3.8.25", "4.0.0-rc4", "4.0.0", "4.0.1", "3.8.26", "3.8.27", "4.0.2", "3.8.28", "4.0.3", "3.8.29", "4.0.4", "3.8.30", "4.0.5", "3.8.31", "4.0.6", "3.8.33", "4.0.7", "3.8.34", "4.0.8", "4.1.0", "4.1.1", "4.1.2", "3.8.35", "4.1.3", "4.1.5", "4.1.6", "4.1.7", "4.1.8", "4.1.9", "4.1.10", "4.1.11", "3.8.36", "4.1.12", "4.2.0", "4.2.1", "4.2.2", "4.2.3", "4.2.4", "4.2.5", "3.8.37", "4.2.6", "4.2.7", "4.2.8", "4.2.9", "4.2.10", "4.3.0", "4.3.1", "4.3.2", "4.3.3", "4.3.4", "3.8.38", "4.3.5", "4.3.6", "3.8.39", "4.3.7", "4.4.0", "4.4.1", "4.4.2", "4.4.3", "4.4.4", "4.4.5", "4.4.6", "4.4.7", "4.4.8", "4.4.9", "4.4.10", "4.4.11", "4.4.12", "4.4.13", "3.8.40", "4.4.14", "4.4.15", "4.4.16", "4.4.17", "4.4.18", "4.4.19", "4.4.20", "4.5.0", "4.5.1", "4.5.2", "4.5.3", "4.5.4", "4.5.5", "4.5.6", "4.5.7", "4.5.8", "4.5.9", "4.5.10", "4.6.0", "4.6.1", "4.6.2", "4.6.3", "4.6.4", "4.6.5", "4.6.6", "4.6.7", "4.6.8", "4.7.0", "4.7.1", "4.7.2", "4.7.3", "4.7.4", "4.7.5-pre", "4.7.5", "4.7.6", "4.7.7", "4.7.8", "4.7.9", "4.8.0", "4.8.1", "4.8.2", "4.8.3", "4.8.4", "4.8.5", "4.8.6", "4.8.7", "4.9.0", "4.9.1", "4.9.2", "4.9.3", "4.9.4", "4.9.5", "4.9.6", "4.9.7", "4.9.8", "4.9.9", "4.9.10", "4.10.0", "4.10.1", "4.10.2", "4.10.3", "4.10.4", "4.10.5", "4.10.6", "4.10.7", "4.10.8", "4.11.0", "4.11.1", "4.11.2", "4.11.3", "4.11.4", "4.11.5", "4.11.6", "4.11.7", "4.11.8", "4.11.9", "4.11.10", "4.11.11", "4.11.12", "4.11.13", "4.11.14", "4.12.0", "4.12.1", "4.12.2", "4.12.3", "4.12.4", "4.12.5", "4.12.6", "4.13.0", "4.13.1", "4.13.2", "4.13.3", "4.13.4", "4.13.5", "4.13.6", "4.13.7", "4.13.8", "5.0.0-rc0", "5.0.0-rc1", "5.0.0-rc2", "4.13.9", "5.0.0", "5.0.1", "4.13.10", "5.0.2", "5.0.3", "4.13.11", "5.0.4", "5.0.5", "5.0.6", "5.0.7", "5.0.8", "5.0.9", "5.0.10", "4.13.12", "5.0.11", "5.0.12", "5.0.13", "5.0.14", "5.0.15", "5.0.16", "5.0.17", "5.0.18", "5.1.0", "5.1.1", "4.13.13", "5.1.2", "4.13.14", "5.1.3", "5.1.4", "5.1.5", "5.1.6", "5.1.7", "5.1.8", "5.2.0", "5.2.1", "5.2.2", "5.2.3", "5.2.4", "5.2.5", "5.2.6", "5.2.7", "5.2.8", "4.13.15", "5.2.9", "5.2.10", "4.13.16", "5.2.11", "4.13.17", "5.2.12", "5.2.13", "5.2.14", "5.2.15", "5.2.16", "5.2.17", "5.2.18", "5.3.0", "5.3.1", "5.3.2", "5.3.3", "5.3.4", "5.3.5", "5.3.6", "5.3.7", "5.3.8", "5.3.9", "5.3.10", "5.3.11", "5.3.12", "5.3.13", "5.3.14", "5.3.15", "5.3.16", "5.4.0", "5.4.1", "5.4.2", "5.4.3", "5.4.4", "5.4.5", "4.13.18", "5.4.6", "5.4.7", "5.4.8", "5.4.9", "5.4.10", "5.4.11", "5.4.12", "5.4.13", "5.4.14", "5.4.15", "5.4.16", "5.4.17", "5.4.18", "5.4.19", "5.4.20", "5.4.21", "5.4.22", "5.4.23", "5.5.0", "5.5.1", "5.5.2", "5.5.3", "5.5.4", "5.5.5", "5.5.6", "5.5.7", "5.5.8", "5.5.9", "5.5.10", "5.5.11", "5.5.12", "5.5.13", "5.5.14", "5.5.15", "5.6.0", "5.6.1", "5.6.2", "5.6.3", "5.6.4", "5.6.5", "4.13.19", "5.6.6", "5.6.7", "5.6.8", "5.6.9", "5.6.10", "5.6.11", "5.6.12", "5.6.13", "5.7.0", "5.7.1", "5.7.3", "5.7.4", "5.7.5", "5.7.6", "5.7.7", "5.7.8", "5.7.9", "5.7.10", "5.7.11", "5.7.12", "5.7.13", "5.7.14", "5.8.0", "5.8.1", "5.8.2", "5.8.3", "5.8.4", "5.8.5", "4.13.20", "5.8.6", "5.8.7", "5.8.9", "5.8.10", "5.8.11", "5.8.12", "5.8.13", "5.9.0", "5.9.1", "5.9.2", "5.9.3", "5.9.4", "5.9.5", "5.9.6", "5.9.7", "5.9.9", "5.9.10", "5.9.11", "5.9.12", "5.9.13", "5.9.14", "5.9.15", "5.9.16", "5.9.17", "5.9.18", "5.9.19", "5.9.20", "5.9.21", "5.9.22", "5.9.23", "4.13.21", "5.9.24", "5.9.25", "5.9.26", "5.9.27", "5.9.28", "5.9.29", "5.10.0", "5.10.1", "5.10.2", "5.10.3", "5.10.4", "5.10.5", "5.10.6", "5.10.7", "5.10.8", "5.10.9", "5.10.10", "5.10.11", "5.10.12", "5.10.13", "5.10.14", "5.10.15", "5.10.16", "5.10.17", "5.10.18", "5.10.19", "5.11.0", "5.11.1", "5.11.2", "5.11.3", "5.11.4", "5.11.5", "5.11.6", "5.11.7", "5.11.8", "5.11.9", "5.11.10", "5.11.11", "5.11.12", "5.11.13", "5.11.14", "5.11.15", "5.11.16", "5.11.17", "5.11.18", "5.11.19", "5.11.20", "5.12.0", "5.12.1", "5.12.2", "5.12.3", "5.12.4", "5.12.5", "5.12.6", "5.12.7", "5.12.8", "5.12.9", "5.12.10", "5.12.11", "5.12.12", "5.12.13", "5.12.14", "5.12.15", "5.13.0", "5.13.1", "5.13.2", "5.13.3", "5.13.4", "5.13.5", "5.13.6", "5.13.7", "5.13.8", "5.13.9", "5.13.10", "5.13.11", "5.13.12", "5.13.13", "5.13.14", "5.13.15", "5.13.16", "5.13.17", "5.13.18", "5.13.19", "6.0.0", "6.0.1", "6.0.2", "6.0.3", "6.0.4", "6.0.5", "6.0.6", "6.0.7", "6.0.8", "6.0.9", "6.0.10", "6.0.11", "6.0.12", "6.0.13", "6.0.14", "6.0.15", "6.1.0", "6.1.1", "6.1.2", "6.1.3", "6.1.4", "6.1.5", "6.1.6", "6.1.7", "6.1.8", "6.1.9", "6.1.10", "6.2.0", "6.2.1", "6.2.2", "6.2.3", "6.2.4", "6.2.5", "6.2.6", "6.2.7", "6.2.8", "6.2.9", "6.2.10", "6.2.11", "6.3.0", "6.3.1", "6.3.2", "6.3.3", "6.3.4", "6.3.5", "6.3.6", "6.3.7", "6.3.8", "6.3.9", "6.4.0", "6.4.1", "6.4.2", "6.4.3", "6.4.4", "6.4.5", "6.4.6", "6.4.7", "6.5.0", "6.5.1", "6.5.2", "6.5.3", "6.5.4", "6.5.5", "6.6.0", "6.6.1", "6.6.2", "6.6.3", "6.6.4", "6.6.5", "6.6.6", "6.6.7", "6.7.0", "6.7.1", "6.7.2", "6.7.3", "6.7.4", "6.7.5", "6.8.0", "6.8.1", "6.8.2", "6.8.3", "6.8.4", "6.9.0", "6.9.1", "6.9.2", "6.9.3", "6.10.0", "6.10.1", "6.10.2", "6.10.3", "6.10.4", "6.10.5", "6.11.0", "6.11.1", "6.11.2", "7.0.0", "7.0.1", "7.0.2", "7.0.3", "7.0.4", "7.0.5", "7.1.0", "7.1.1", "7.1.2", "7.2.0", "7.2.1", "7.2.2", "7.2.3", "7.2.4", "7.3.0", "7.3.1", "7.3.2"]
Secure versions: [6.0.0-rc0, 6.0.0-rc1, 6.0.0-rc2, 7.0.0-rc0, 7.3.3, 6.11.3, 5.13.20, 7.3.4, 6.11.4, 7.4.0, 7.4.1, 6.11.5, 7.4.2, 7.4.3, 6.11.6, 7.4.4, 6.12.0, 7.4.5, 7.5.0, 7.5.1, 7.5.2, 7.5.3, 7.5.4, 7.6.0, 7.6.1, 6.12.1, 7.6.2, 7.6.3, 5.13.21, 8.0.0-rc0, 6.12.2, 7.6.4, 8.0.0, 6.12.3, 7.6.5, 8.0.1, 7.6.6, 8.0.2, 7.6.7, 8.0.3, 6.12.4, 5.13.22, 6.12.5, 7.6.8, 8.0.4, 8.1.0, 6.12.6, 8.1.1, 8.1.2, 8.1.3, 8.2.0, 7.6.9, 6.12.7, 8.2.1, 7.6.10, 8.2.2, 8.2.3, 8.2.4, 8.3.0, 8.3.1, 6.12.8, 7.6.11, 8.3.2, 8.3.3, 8.3.4, 8.3.5, 8.4.0, 7.6.12, 6.12.9, 8.4.1, 7.6.13, 6.13.0, 8.4.2, 8.4.3, 7.7.0, 8.4.4, 8.4.5, 8.5.0, 8.5.1, 7.8.0, 8.5.2, 8.5.3, 7.8.1, 8.5.4, 8.5.5, 8.6.0, 8.6.1, 6.13.1, 8.6.2, 6.13.2, 8.6.3, 6.13.3, 7.8.2, 8.6.4, 8.7.0, 8.7.1, 8.7.2, 8.7.3]
Recommendation: Update to version 8.7.3.

automattic/mongoose vulnerable to Prototype pollution via Schema.path

Published date: 2022-07-29T00:00:18Z
CVE: CVE-2022-2564
Links:

Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Affected versions of this package are vulnerable to Prototype Pollution. The Schema.path() function is vulnerable to prototype pollution when setting the schema object. This vulnerability allows modification of the Object prototype and could be manipulated into a Denial of Service (DoS) attack.

Affected versions: ["0.0.1", "0.0.2", "0.0.3", "0.0.4", "0.0.5", "1.0.0", "1.0.1", "1.0.2", "0.0.6", "1.0.3", "1.0.4", "1.0.5", "1.0.6", "1.0.7", "1.0.8", "1.0.10", "1.0.11", "1.0.12", "1.0.13", "1.0.14", "1.0.15", "1.0.16", "1.1.0", "1.1.1", "1.1.2", "1.1.3", "1.1.4", "1.1.5", "1.1.6", "1.1.7", "1.1.8", "1.1.9", "1.1.10", "1.1.11", "1.1.12", "1.1.13", "1.1.14", "1.1.15", "1.1.16", "1.1.17", "1.1.18", "1.1.19", "1.1.20", "1.1.21", "1.1.22", "1.1.23", "1.1.24", "1.1.25", "1.2.0", "1.3.0", "1.3.1", "1.3.2", "1.3.3", "1.3.4", "1.3.5", "1.3.6", "1.3.7", "1.4.0", "1.5.0", "1.6.0", "1.7.2", "1.7.3", "1.7.4", "1.8.0", "1.8.1", "1.8.2", "1.8.3", "1.8.4", "2.0.0", "2.0.1", "2.0.2", "2.0.3", "2.0.4", "2.1.0", "2.1.1", "2.1.2", "2.1.3", "2.1.4", "2.2.0", "2.2.1", "2.2.2", "2.2.3", "2.2.4", "2.3.0", "2.3.1", "2.3.2", "2.3.3", "2.3.4", "2.3.5", "2.3.6", "2.3.7", "2.3.8", "2.3.9", "2.3.10", "2.3.11", "2.3.12", "2.3.13", "2.4.0", "2.4.1", "2.4.2", "2.4.3", "2.4.4", "2.4.5", "2.4.6", "2.4.7", "2.4.8", "2.4.9", "2.4.10", "2.5.0", "2.5.1", "2.5.2", "2.5.3", "2.5.4", "2.5.5", "2.5.6", "2.5.7", "2.5.8", "2.5.9", "2.5.10", "2.5.11", "2.5.12", "2.5.13", "2.5.14", "2.6.0", "2.6.1", "2.6.2", "2.6.3", "2.6.4", "2.6.5", "2.6.6", "2.6.7", "2.6.8", "2.7.0", "2.7.1", "2.7.2", "2.7.4", "2.7.3", "3.0.0", "3.0.1", "3.0.2", "2.8.0", "3.0.3", "3.1.0", "2.8.1", "3.1.1", "2.8.2", "2.8.3", "2.9.0", "3.2.0", "2.9.1", "3.2.1", "2.9.2", "3.2.2", "3.3.0", "3.3.1", "2.9.3", "3.4.0", "2.9.4", "2.9.5", "3.5.0", "3.5.1", "3.5.2", "3.5.3", "2.9.6", "2.9.7", "3.5.4", "3.5.5", "2.9.8", "2.9.9", "3.5.6", "3.5.7", "3.5.8", "2.9.10", "3.5.9", "3.6.2", "3.5.10", "3.6.3", "3.5.11", "3.6.4", "3.6.5", "3.6.6", "3.6.7", "3.5.12", "3.6.8", "3.6.9", "3.6.10", "3.5.13", "3.5.14", "3.6.11", "3.6.12", "3.6.13", "3.6.14", "3.6.15", "3.5.15", "3.7.0", "3.6.16", "3.5.16", "3.6.17", "3.7.2", "3.0.0-alpha1", "3.0.0-alpha2", "3.0.0-rc0", "3.6.0-rc0", "3.6.0-rc1", "3.6.18", "3.7.3", "3.6.19", "3.6.20", "3.7.4", "3.8.0", "3.8.1", "3.8.2", "3.8.3", "3.8.4", "3.8.5", "3.8.6", "3.8.7", "3.8.8", "3.8.9", "3.8.10", "3.8.11", "3.9.0", "3.8.12", "3.8.13", "3.8.14", "3.8.15", "3.9.1", "3.8.16", "3.9.2", "3.8.17", "3.9.3", "3.8.18", "3.9.4", "3.8.19", "3.9.5", "3.8.20", "3.9.6", "3.8.21", "3.9.7", "3.8.22", "4.0.0-rc0", "4.0.0-rc1", "3.8.23", "4.0.0-rc2", "3.8.24", "4.0.0-rc3", "3.8.25", "4.0.0-rc4", "4.0.0", "4.0.1", "3.8.26", "3.8.27", "4.0.2", "3.8.28", "4.0.3", "3.8.29", "4.0.4", "3.8.30", "4.0.5", "3.8.31", "4.0.6", "3.8.33", "4.0.7", "3.8.34", "4.0.8", "4.1.0", "4.1.1", "4.1.2", "3.8.35", "4.1.3", "4.1.5", "4.1.6", "4.1.7", "4.1.8", "4.1.9", "4.1.10", "4.1.11", "3.8.36", "4.1.12", "4.2.0", "4.2.1", "4.2.2", "4.2.3", "4.2.4", "4.2.5", "3.8.37", "4.2.6", "4.2.7", "4.2.8", "4.2.9", "4.2.10", "4.3.0", "4.3.1", "4.3.2", "4.3.3", "4.3.4", "3.8.38", "4.3.5", "4.3.6", "3.8.39", "4.3.7", "4.4.0", "4.4.1", "4.4.2", "4.4.3", "4.4.4", "4.4.5", "4.4.6", "4.4.7", "4.4.8", "4.4.9", "4.4.10", "4.4.11", "4.4.12", "4.4.13", "3.8.40", "4.4.14", "4.4.15", "4.4.16", "4.4.17", "4.4.18", "4.4.19", "4.4.20", "4.5.0", "4.5.1", "4.5.2", "4.5.3", "4.5.4", "4.5.5", "4.5.6", "4.5.7", "4.5.8", "4.5.9", "4.5.10", "4.6.0", "4.6.1", "4.6.2", "4.6.3", "4.6.4", "4.6.5", "4.6.6", "4.6.7", "4.6.8", "4.7.0", "4.7.1", "4.7.2", "4.7.3", "4.7.4", "4.7.5-pre", "4.7.5", "4.7.6", "4.7.7", "4.7.8", "4.7.9", "4.8.0", "4.8.1", "4.8.2", "4.8.3", "4.8.4", "4.8.5", "4.8.6", "4.8.7", "4.9.0", "4.9.1", "4.9.2", "4.9.3", "4.9.4", "4.9.5", "4.9.6", "4.9.7", "4.9.8", "4.9.9", "4.9.10", "4.10.0", "4.10.1", "4.10.2", "4.10.3", "4.10.4", "4.10.5", "4.10.6", "4.10.7", "4.10.8", "4.11.0", "4.11.1", "4.11.2", "4.11.3", "4.11.4", "4.11.5", "4.11.6", "4.11.7", "4.11.8", "4.11.9", "4.11.10", "4.11.11", "4.11.12", "4.11.13", "4.11.14", "4.12.0", "4.12.1", "4.12.2", "4.12.3", "4.12.4", "4.12.5", "4.12.6", "4.13.0", "4.13.1", "4.13.2", "4.13.3", "4.13.4", "4.13.5", "4.13.6", "4.13.7", "4.13.8", "5.0.0-rc0", "5.0.0-rc1", "5.0.0-rc2", "4.13.9", "5.0.0", "5.0.1", "4.13.10", "5.0.2", "5.0.3", "4.13.11", "5.0.4", "5.0.5", "5.0.6", "5.0.7", "5.0.8", "5.0.9", "5.0.10", "4.13.12", "5.0.11", "5.0.12", "5.0.13", "5.0.14", "5.0.15", "5.0.16", "5.0.17", "5.0.18", "5.1.0", "5.1.1", "4.13.13", "5.1.2", "4.13.14", "5.1.3", "5.1.4", "5.1.5", "5.1.6", "5.1.7", "5.1.8", "5.2.0", "5.2.1", "5.2.2", "5.2.3", "5.2.4", "5.2.5", "5.2.6", "5.2.7", "5.2.8", "4.13.15", "5.2.9", "5.2.10", "4.13.16", "5.2.11", "4.13.17", "5.2.12", "5.2.13", "5.2.14", "5.2.15", "5.2.16", "5.2.17", "5.2.18", "5.3.0", "5.3.1", "5.3.2", "5.3.3", "5.3.4", "5.3.5", "5.3.6", "5.3.7", "5.3.8", "5.3.9", "5.3.10", "5.3.11", "5.3.12", "5.3.13", "5.3.14", "5.3.15", "5.3.16", "5.4.0", "5.4.1", "5.4.2", "5.4.3", "5.4.4", "5.4.5", "4.13.18", "5.4.6", "5.4.7", "5.4.8", "5.4.9", "5.4.10", "5.4.11", "5.4.12", "5.4.13", "5.4.14", "5.4.15", "5.4.16", "5.4.17", "5.4.18", "5.4.19", "5.4.20", "5.4.21", "5.4.22", "5.4.23", "5.5.0", "5.5.1", "5.5.2", "5.5.3", "5.5.4", "5.5.5", "5.5.6", "5.5.7", "5.5.8", "5.5.9", "5.5.10", "5.5.11", "5.5.12", "5.5.13", "5.5.14", "5.5.15", "5.6.0", "5.6.1", "5.6.2", "5.6.3", "5.6.4", "5.6.5", "4.13.19", "5.6.6", "5.6.7", "5.6.8", "5.6.9", "5.6.10", "5.6.11", "5.6.12", "5.6.13", "5.7.0", "5.7.1", "5.7.3", "5.7.4", "5.7.5", "5.7.6", "5.7.7", "5.7.8", "5.7.9", "5.7.10", "5.7.11", "5.7.12", "5.7.13", "5.7.14", "5.8.0", "5.8.1", "5.8.2", "5.8.3", "5.8.4", "5.8.5", "4.13.20", "5.8.6", "5.8.7", "5.8.9", "5.8.10", "5.8.11", "5.8.12", "5.8.13", "5.9.0", "5.9.1", "5.9.2", "5.9.3", "5.9.4", "5.9.5", "5.9.6", "5.9.7", "5.9.9", "5.9.10", "5.9.11", "5.9.12", "5.9.13", "5.9.14", "5.9.15", "5.9.16", "5.9.17", "5.9.18", "5.9.19", "5.9.20", "5.9.21", "5.9.22", "5.9.23", "4.13.21", "5.9.24", "5.9.25", "5.9.26", "5.9.27", "5.9.28", "5.9.29", "5.10.0", "5.10.1", "5.10.2", "5.10.3", "5.10.4", "5.10.5", "5.10.6", "5.10.7", "5.10.8", "5.10.9", "5.10.10", "5.10.11", "5.10.12", "5.10.13", "5.10.14", "5.10.15", "5.10.16", "5.10.17", "5.10.18", "5.10.19", "5.11.0", "5.11.1", "5.11.2", "5.11.3", "5.11.4", "5.11.5", "5.11.6", "5.11.7", "5.11.8", "5.11.9", "5.11.10", "5.11.11", "5.11.12", "5.11.13", "5.11.14", "5.11.15", "5.11.16", "5.11.17", "5.11.18", "5.11.19", "5.11.20", "5.12.0", "5.12.1", "5.12.2", "5.12.3", "5.12.4", "5.12.5", "5.12.6", "5.12.7", "5.12.8", "5.12.9", "5.12.10", "5.12.11", "5.12.12", "5.12.13", "5.12.14", "5.12.15", "5.13.0", "5.13.1", "5.13.2", "5.13.3", "5.13.4", "5.13.5", "5.13.6", "5.13.7", "5.13.8", "5.13.9", "5.13.10", "5.13.11", "5.13.12", "5.13.13", "5.13.14", "6.0.0", "6.0.1", "6.0.2", "6.0.3", "6.0.4", "6.0.5", "6.0.6", "6.0.7", "6.0.8", "6.0.9", "6.0.10", "6.0.11", "6.0.12", "6.0.13", "6.0.14", "6.0.15", "6.1.0", "6.1.1", "6.1.2", "6.1.3", "6.1.4", "6.1.5", "6.1.6", "6.1.7", "6.1.8", "6.1.9", "6.1.10", "6.2.0", "6.2.1", "6.2.2", "6.2.3", "6.2.4", "6.2.5", "6.2.6", "6.2.7", "6.2.8", "6.2.9", "6.2.10", "6.2.11", "6.3.0", "6.3.1", "6.3.2", "6.3.3", "6.3.4", "6.3.5", "6.3.6", "6.3.7", "6.3.8", "6.3.9", "6.4.0", "6.4.1", "6.4.2", "6.4.3", "6.4.4", "6.4.5"]
Secure versions: [6.0.0-rc0, 6.0.0-rc1, 6.0.0-rc2, 7.0.0-rc0, 7.3.3, 6.11.3, 5.13.20, 7.3.4, 6.11.4, 7.4.0, 7.4.1, 6.11.5, 7.4.2, 7.4.3, 6.11.6, 7.4.4, 6.12.0, 7.4.5, 7.5.0, 7.5.1, 7.5.2, 7.5.3, 7.5.4, 7.6.0, 7.6.1, 6.12.1, 7.6.2, 7.6.3, 5.13.21, 8.0.0-rc0, 6.12.2, 7.6.4, 8.0.0, 6.12.3, 7.6.5, 8.0.1, 7.6.6, 8.0.2, 7.6.7, 8.0.3, 6.12.4, 5.13.22, 6.12.5, 7.6.8, 8.0.4, 8.1.0, 6.12.6, 8.1.1, 8.1.2, 8.1.3, 8.2.0, 7.6.9, 6.12.7, 8.2.1, 7.6.10, 8.2.2, 8.2.3, 8.2.4, 8.3.0, 8.3.1, 6.12.8, 7.6.11, 8.3.2, 8.3.3, 8.3.4, 8.3.5, 8.4.0, 7.6.12, 6.12.9, 8.4.1, 7.6.13, 6.13.0, 8.4.2, 8.4.3, 7.7.0, 8.4.4, 8.4.5, 8.5.0, 8.5.1, 7.8.0, 8.5.2, 8.5.3, 7.8.1, 8.5.4, 8.5.5, 8.6.0, 8.6.1, 6.13.1, 8.6.2, 6.13.2, 8.6.3, 6.13.3, 7.8.2, 8.6.4, 8.7.0, 8.7.1, 8.7.2, 8.7.3]
Recommendation: Update to version 8.7.3.

Mongoose Vulnerable to Prototype Pollution in Schema Object

Published date: 2022-08-27T00:00:54Z
CVE: CVE-2022-24304
Links:

Description

Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment.

Affected versions of this package are vulnerable to Prototype Pollution. The Schema.path() function is vulnerable to prototype pollution when setting the schema object. This vulnerability allows modification of the Object prototype and could be manipulated into a Denial of Service (DoS) attack.

Proof of Concept

// poc.js
const mongoose = require('mongoose');
const schema = new mongoose.Schema();

malicious_payload = '__proto__.toString'

schema.path(malicious_payload, [String])

x = {}
console.log(x.toString()) // crashed (Denial of service (DoS) attack)

Impact

This vulnerability can be manipulated to exploit other types of attacks, such as Denial of service (DoS), Remote Code Execution, or Property Injection.

Affected versions: ["0.0.1", "0.0.2", "0.0.3", "0.0.4", "0.0.5", "1.0.0", "1.0.1", "1.0.2", "0.0.6", "1.0.3", "1.0.4", "1.0.5", "1.0.6", "1.0.7", "1.0.8", "1.0.10", "1.0.11", "1.0.12", "1.0.13", "1.0.14", "1.0.15", "1.0.16", "1.1.0", "1.1.1", "1.1.2", "1.1.3", "1.1.4", "1.1.5", "1.1.6", "1.1.7", "1.1.8", "1.1.9", "1.1.10", "1.1.11", "1.1.12", "1.1.13", "1.1.14", "1.1.15", "1.1.16", "1.1.17", "1.1.18", "1.1.19", "1.1.20", "1.1.21", "1.1.22", "1.1.23", "1.1.24", "1.1.25", "1.2.0", "1.3.0", "1.3.1", "1.3.2", "1.3.3", "1.3.4", "1.3.5", "1.3.6", "1.3.7", "1.4.0", "1.5.0", "1.6.0", "1.7.2", "1.7.3", "1.7.4", "1.8.0", "1.8.1", "1.8.2", "1.8.3", "1.8.4", "2.0.0", "2.0.1", "2.0.2", "2.0.3", "2.0.4", "2.1.0", "2.1.1", "2.1.2", "2.1.3", "2.1.4", "2.2.0", "2.2.1", "2.2.2", "2.2.3", "2.2.4", "2.3.0", "2.3.1", "2.3.2", "2.3.3", "2.3.4", "2.3.5", "2.3.6", "2.3.7", "2.3.8", "2.3.9", "2.3.10", "2.3.11", "2.3.12", "2.3.13", "2.4.0", "2.4.1", "2.4.2", "2.4.3", "2.4.4", "2.4.5", "2.4.6", "2.4.7", "2.4.8", "2.4.9", "2.4.10", "2.5.0", "2.5.1", "2.5.2", "2.5.3", "2.5.4", "2.5.5", "2.5.6", "2.5.7", "2.5.8", "2.5.9", "2.5.10", "2.5.11", "2.5.12", "2.5.13", "2.5.14", "2.6.0", "2.6.1", "2.6.2", "2.6.3", "2.6.4", "2.6.5", "2.6.6", "2.6.7", "2.6.8", "2.7.0", "2.7.1", "2.7.2", "2.7.4", "2.7.3", "3.0.0", "3.0.1", "3.0.2", "2.8.0", "3.0.3", "3.1.0", "2.8.1", "3.1.1", "2.8.2", "2.8.3", "2.9.0", "3.2.0", "2.9.1", "3.2.1", "2.9.2", "3.2.2", "3.3.0", "3.3.1", "2.9.3", "3.4.0", "2.9.4", "2.9.5", "3.5.0", "3.5.1", "3.5.2", "3.5.3", "2.9.6", "2.9.7", "3.5.4", "3.5.5", "2.9.8", "2.9.9", "3.5.6", "3.5.7", "3.5.8", "2.9.10", "3.5.9", "3.6.2", "3.5.10", "3.6.3", "3.5.11", "3.6.4", "3.6.5", "3.6.6", "3.6.7", "3.5.12", "3.6.8", "3.6.9", "3.6.10", "3.5.13", "3.5.14", "3.6.11", "3.6.12", "3.6.13", "3.6.14", "3.6.15", "3.5.15", "3.7.0", "3.6.16", "3.5.16", "3.6.17", "3.7.2", "3.0.0-alpha1", "3.0.0-alpha2", "3.0.0-rc0", "3.6.0-rc0", "3.6.0-rc1", "3.6.18", "3.7.3", "3.6.19", "3.6.20", "3.7.4", "3.8.0", "3.8.1", "3.8.2", "3.8.3", "3.8.4", "3.8.5", "3.8.6", "3.8.7", "3.8.8", "3.8.9", "3.8.10", "3.8.11", "3.9.0", "3.8.12", "3.8.13", "3.8.14", "3.8.15", "3.9.1", "3.8.16", "3.9.2", "3.8.17", "3.9.3", "3.8.18", "3.9.4", "3.8.19", "3.9.5", "3.8.20", "3.9.6", "3.8.21", "3.9.7", "3.8.22", "4.0.0-rc0", "4.0.0-rc1", "3.8.23", "4.0.0-rc2", "3.8.24", "4.0.0-rc3", "3.8.25", "4.0.0-rc4", "4.0.0", "4.0.1", "3.8.26", "3.8.27", "4.0.2", "3.8.28", "4.0.3", "3.8.29", "4.0.4", "3.8.30", "4.0.5", "3.8.31", "4.0.6", "3.8.33", "4.0.7", "3.8.34", "4.0.8", "4.1.0", "4.1.1", "4.1.2", "3.8.35", "4.1.3", "4.1.5", "4.1.6", "4.1.7", "4.1.8", "4.1.9", "4.1.10", "4.1.11", "3.8.36", "4.1.12", "4.2.0", "4.2.1", "4.2.2", "4.2.3", "4.2.4", "4.2.5", "3.8.37", "4.2.6", "4.2.7", "4.2.8", "4.2.9", "4.2.10", "4.3.0", "4.3.1", "4.3.2", "4.3.3", "4.3.4", "3.8.38", "4.3.5", "4.3.6", "3.8.39", "4.3.7", "4.4.0", "4.4.1", "4.4.2", "4.4.3", "4.4.4", "4.4.5", "4.4.6", "4.4.7", "4.4.8", "4.4.9", "4.4.10", "4.4.11", "4.4.12", "4.4.13", "3.8.40", "4.4.14", "4.4.15", "4.4.16", "4.4.17", "4.4.18", "4.4.19", "4.4.20", "4.5.0", "4.5.1", "4.5.2", "4.5.3", "4.5.4", "4.5.5", "4.5.6", "4.5.7", "4.5.8", "4.5.9", "4.5.10", "4.6.0", "4.6.1", "4.6.2", "4.6.3", "4.6.4", "4.6.5", "4.6.6", "4.6.7", "4.6.8", "4.7.0", "4.7.1", "4.7.2", "4.7.3", "4.7.4", "4.7.5-pre", "4.7.5", "4.7.6", "4.7.7", "4.7.8", "4.7.9", "4.8.0", "4.8.1", "4.8.2", "4.8.3", "4.8.4", "4.8.5", "4.8.6", "4.8.7", "4.9.0", "4.9.1", "4.9.2", "4.9.3", "4.9.4", "4.9.5", "4.9.6", "4.9.7", "4.9.8", "4.9.9", "4.9.10", "4.10.0", "4.10.1", "4.10.2", "4.10.3", "4.10.4", "4.10.5", "4.10.6", "4.10.7", "4.10.8", "4.11.0", "4.11.1", "4.11.2", "4.11.3", "4.11.4", "4.11.5", "4.11.6", "4.11.7", "4.11.8", "4.11.9", "4.11.10", "4.11.11", "4.11.12", "4.11.13", "4.11.14", "4.12.0", "4.12.1", "4.12.2", "4.12.3", "4.12.4", "4.12.5", "4.12.6", "4.13.0", "4.13.1", "4.13.2", "4.13.3", "4.13.4", "4.13.5", "4.13.6", "4.13.7", "4.13.8", "5.0.0-rc0", "5.0.0-rc1", "5.0.0-rc2", "4.13.9", "5.0.0", "5.0.1", "4.13.10", "5.0.2", "5.0.3", "4.13.11", "5.0.4", "5.0.5", "5.0.6", "5.0.7", "5.0.8", "5.0.9", "5.0.10", "4.13.12", "5.0.11", "5.0.12", "5.0.13", "5.0.14", "5.0.15", "5.0.16", "5.0.17", "5.0.18", "5.1.0", "5.1.1", "4.13.13", "5.1.2", "4.13.14", "5.1.3", "5.1.4", "5.1.5", "5.1.6", "5.1.7", "5.1.8", "5.2.0", "5.2.1", "5.2.2", "5.2.3", "5.2.4", "5.2.5", "5.2.6", "5.2.7", "5.2.8", "4.13.15", "5.2.9", "5.2.10", "4.13.16", "5.2.11", "4.13.17", "5.2.12", "5.2.13", "5.2.14", "5.2.15", "5.2.16", "5.2.17", "5.2.18", "5.3.0", "5.3.1", "5.3.2", "5.3.3", "5.3.4", "5.3.5", "5.3.6", "5.3.7", "5.3.8", "5.3.9", "5.3.10", "5.3.11", "5.3.12", "5.3.13", "5.3.14", "5.3.15", "5.3.16", "5.4.0", "5.4.1", "5.4.2", "5.4.3", "5.4.4", "5.4.5", "4.13.18", "5.4.6", "5.4.7", "5.4.8", "5.4.9", "5.4.10", "5.4.11", "5.4.12", "5.4.13", "5.4.14", "5.4.15", "5.4.16", "5.4.17", "5.4.18", "5.4.19", "5.4.20", "5.4.21", "5.4.22", "5.4.23", "5.5.0", "5.5.1", "5.5.2", "5.5.3", "5.5.4", "5.5.5", "5.5.6", "5.5.7", "5.5.8", "5.5.9", "5.5.10", "5.5.11", "5.5.12", "5.5.13", "5.5.14", "5.5.15", "5.6.0", "5.6.1", "5.6.2", "5.6.3", "5.6.4", "5.6.5", "4.13.19", "5.6.6", "5.6.7", "5.6.8", "5.6.9", "5.6.10", "5.6.11", "5.6.12", "5.6.13", "5.7.0", "5.7.1", "5.7.3", "5.7.4", "5.7.5", "5.7.6", "5.7.7", "5.7.8", "5.7.9", "5.7.10", "5.7.11", "5.7.12", "5.7.13", "5.7.14", "5.8.0", "5.8.1", "5.8.2", "5.8.3", "5.8.4", "5.8.5", "4.13.20", "5.8.6", "5.8.7", "5.8.9", "5.8.10", "5.8.11", "5.8.12", "5.8.13", "5.9.0", "5.9.1", "5.9.2", "5.9.3", "5.9.4", "5.9.5", "5.9.6", "5.9.7", "5.9.9", "5.9.10", "5.9.11", "5.9.12", "5.9.13", "5.9.14", "5.9.15", "5.9.16", "5.9.17", "5.9.18", "5.9.19", "5.9.20", "5.9.21", "5.9.22", "5.9.23", "4.13.21", "5.9.24", "5.9.25", "5.9.26", "5.9.27", "5.9.28", "5.9.29", "5.10.0", "5.10.1", "5.10.2", "5.10.3", "5.10.4", "5.10.5", "5.10.6", "5.10.7", "5.10.8", "5.10.9", "5.10.10", "5.10.11", "5.10.12", "5.10.13", "5.10.14", "5.10.15", "5.10.16", "5.10.17", "5.10.18", "5.10.19", "5.11.0", "5.11.1", "5.11.2", "5.11.3", "5.11.4", "5.11.5", "5.11.6", "5.11.7", "5.11.8", "5.11.9", "5.11.10", "5.11.11", "5.11.12", "5.11.13", "5.11.14", "5.11.15", "5.11.16", "5.11.17", "5.11.18", "5.11.19", "5.11.20", "5.12.0", "5.12.1", "5.12.2", "5.12.3", "5.12.4", "5.12.5", "5.12.6", "5.12.7", "5.12.8", "5.12.9", "5.12.10", "5.12.11", "5.12.12", "5.12.13", "5.12.14", "5.12.15", "5.13.0", "5.13.1", "5.13.2", "5.13.3", "5.13.4", "5.13.5", "5.13.6", "5.13.7", "5.13.8", "5.13.9", "5.13.10", "5.13.11", "5.13.12", "5.13.13", "5.13.14", "6.0.0", "6.0.1", "6.0.2", "6.0.3", "6.0.4", "6.0.5", "6.0.6", "6.0.7", "6.0.8", "6.0.9", "6.0.10", "6.0.11", "6.0.12", "6.0.13", "6.0.14", "6.0.15", "6.1.0", "6.1.1", "6.1.2", "6.1.3", "6.1.4", "6.1.5", "6.1.6", "6.1.7", "6.1.8", "6.1.9", "6.1.10", "6.2.0", "6.2.1", "6.2.2", "6.2.3", "6.2.4", "6.2.5", "6.2.6", "6.2.7", "6.2.8", "6.2.9", "6.2.10", "6.2.11", "6.3.0", "6.3.1", "6.3.2", "6.3.3", "6.3.4", "6.3.5", "6.3.6", "6.3.7", "6.3.8", "6.3.9", "6.4.0", "6.4.1", "6.4.2", "6.4.3", "6.4.4", "6.4.5"]
Secure versions: [6.0.0-rc0, 6.0.0-rc1, 6.0.0-rc2, 7.0.0-rc0, 7.3.3, 6.11.3, 5.13.20, 7.3.4, 6.11.4, 7.4.0, 7.4.1, 6.11.5, 7.4.2, 7.4.3, 6.11.6, 7.4.4, 6.12.0, 7.4.5, 7.5.0, 7.5.1, 7.5.2, 7.5.3, 7.5.4, 7.6.0, 7.6.1, 6.12.1, 7.6.2, 7.6.3, 5.13.21, 8.0.0-rc0, 6.12.2, 7.6.4, 8.0.0, 6.12.3, 7.6.5, 8.0.1, 7.6.6, 8.0.2, 7.6.7, 8.0.3, 6.12.4, 5.13.22, 6.12.5, 7.6.8, 8.0.4, 8.1.0, 6.12.6, 8.1.1, 8.1.2, 8.1.3, 8.2.0, 7.6.9, 6.12.7, 8.2.1, 7.6.10, 8.2.2, 8.2.3, 8.2.4, 8.3.0, 8.3.1, 6.12.8, 7.6.11, 8.3.2, 8.3.3, 8.3.4, 8.3.5, 8.4.0, 7.6.12, 6.12.9, 8.4.1, 7.6.13, 6.13.0, 8.4.2, 8.4.3, 7.7.0, 8.4.4, 8.4.5, 8.5.0, 8.5.1, 7.8.0, 8.5.2, 8.5.3, 7.8.1, 8.5.4, 8.5.5, 8.6.0, 8.6.1, 6.13.1, 8.6.2, 6.13.2, 8.6.3, 6.13.3, 7.8.2, 8.6.4, 8.7.0, 8.7.1, 8.7.2, 8.7.3]
Recommendation: Update to version 8.7.3.

Remote Memory Exposure

Published date: 2016-01-15
CVSS Score: 6.5
CVSS Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H
Links:

Trying to save a number to a field of type Buffer on the affected mongoose versions allocates a chunk of uninitialized memory and stores it in the database.

Affected versions: ["3.5.5", "3.5.6", "3.5.7", "3.5.8", "3.5.9", "3.6.2", "3.5.10", "3.6.3", "3.5.11", "3.6.4", "3.6.5", "3.6.6", "3.6.7", "3.5.12", "3.6.8", "3.6.9", "3.6.10", "3.5.13", "3.5.14", "3.6.11", "3.6.12", "3.6.13", "3.6.14", "3.6.15", "3.5.15", "3.7.0", "3.6.16", "3.5.16", "3.6.17", "3.7.2", "3.6.0-rc0", "3.6.0-rc1", "3.6.18", "3.7.3", "3.6.19", "3.6.20", "3.7.4", "3.8.0", "3.8.1", "3.8.2", "3.8.3", "3.8.4", "3.8.5", "3.8.6", "3.8.7", "3.8.8", "3.8.9", "3.8.10", "3.8.11", "3.8.12", "3.8.13", "3.8.14", "3.8.15", "3.8.16", "3.8.17", "3.8.18", "3.8.19", "3.8.20", "3.8.21", "3.8.22", "3.8.23", "3.8.24", "3.8.25", "3.8.26", "3.8.27", "3.8.28", "3.8.29", "3.8.30", "3.8.31", "3.8.33", "3.8.34", "3.8.35", "3.8.36", "3.8.37", "3.8.38", "4.0.0", "4.0.1", "4.0.2", "4.0.3", "4.0.4", "4.0.5", "4.0.6", "4.0.7", "4.0.8", "4.1.0", "4.1.1", "4.1.2", "4.1.3", "4.1.5", "4.1.6", "4.1.7", "4.1.8", "4.1.9", "4.1.10", "4.1.11", "4.1.12", "4.2.0", "4.2.1", "4.2.2", "4.2.3", "4.2.4", "4.2.5", "4.2.6", "4.2.7", "4.2.8", "4.2.9", "4.2.10", "4.3.0", "4.3.1", "4.3.2", "4.3.3", "4.3.4", "4.3.5", "0.0.1", "0.0.2", "0.0.3", "0.0.4", "0.0.5", "1.0.0", "1.0.1", "1.0.2", "0.0.6", "1.0.3", "1.0.4", "1.0.5", "1.0.6", "1.0.7", "1.0.8", "1.0.10", "1.0.11", "1.0.12", "1.0.13", "1.0.14", "1.0.15", "1.0.16", "1.1.0", "1.1.1", "1.1.2", "1.1.3", "1.1.4", "1.1.5", "1.1.6", "1.1.7", "1.1.8", "1.1.9", "1.1.10", "1.1.11", "1.1.12", "1.1.13", "1.1.14", "1.1.15", "1.1.16", "1.1.17", "1.1.18", "1.1.19", "1.1.20", "1.1.21", "1.1.22", "1.1.23", "1.1.24", "1.1.25", "1.2.0", "1.3.0", "1.3.1", "1.3.2", "1.3.3", "1.3.4", "1.3.5", "1.3.6", "1.3.7", "1.4.0", "1.5.0", "1.6.0", "1.7.2", "1.7.3", "1.7.4", "1.8.0", "1.8.1", "1.8.2", "1.8.3", "1.8.4", "2.0.0", "2.0.1", "2.0.2", "2.0.3", "2.0.4", "2.1.0", "2.1.1", "2.1.2", "2.1.3", "2.1.4", "2.2.0", "2.2.1", "2.2.2", "2.2.3", "2.2.4", "2.3.0", "2.3.1", "2.3.2", "2.3.3", "2.3.4", "2.3.5", "2.3.6", "2.3.7", "2.3.8", "2.3.9", "2.3.10", "2.3.11", "2.3.12", "2.3.13", "2.4.0", "2.4.1", "2.4.2", "2.4.3", "2.4.4", "2.4.5", "2.4.6", "2.4.7", "2.4.8", "2.4.9", "2.4.10", "2.5.0", "2.5.1", "2.5.2", "2.5.3", "2.5.4", "2.5.5", "2.5.6", "2.5.7", "2.5.8", "2.5.9", "2.5.10", "2.5.11", "2.5.12", "2.5.13", "2.5.14", "2.6.0", "2.6.1", "2.6.2", "2.6.3", "2.6.4", "2.6.5", "2.6.6", "2.6.7", "2.6.8", "2.7.0", "2.7.1", "2.7.2", "2.7.4", "2.7.3", "3.0.0", "3.0.1", "3.0.2", "2.8.0", "3.0.3", "3.1.0", "2.8.1", "3.1.1", "2.8.2", "2.8.3", "2.9.0", "3.2.0", "2.9.1", "3.2.1", "2.9.2", "3.2.2", "3.3.0", "3.3.1", "2.9.3", "3.4.0", "2.9.4", "2.9.5", "3.5.0", "3.5.1", "3.5.2", "3.5.3", "2.9.6", "2.9.7", "3.5.4", "2.9.8", "2.9.9", "2.9.10", "3.0.0-alpha1", "3.0.0-alpha2", "3.0.0-rc0"]
Secure versions: [6.0.0-rc0, 6.0.0-rc1, 6.0.0-rc2, 7.0.0-rc0, 7.3.3, 6.11.3, 5.13.20, 7.3.4, 6.11.4, 7.4.0, 7.4.1, 6.11.5, 7.4.2, 7.4.3, 6.11.6, 7.4.4, 6.12.0, 7.4.5, 7.5.0, 7.5.1, 7.5.2, 7.5.3, 7.5.4, 7.6.0, 7.6.1, 6.12.1, 7.6.2, 7.6.3, 5.13.21, 8.0.0-rc0, 6.12.2, 7.6.4, 8.0.0, 6.12.3, 7.6.5, 8.0.1, 7.6.6, 8.0.2, 7.6.7, 8.0.3, 6.12.4, 5.13.22, 6.12.5, 7.6.8, 8.0.4, 8.1.0, 6.12.6, 8.1.1, 8.1.2, 8.1.3, 8.2.0, 7.6.9, 6.12.7, 8.2.1, 7.6.10, 8.2.2, 8.2.3, 8.2.4, 8.3.0, 8.3.1, 6.12.8, 7.6.11, 8.3.2, 8.3.3, 8.3.4, 8.3.5, 8.4.0, 7.6.12, 6.12.9, 8.4.1, 7.6.13, 6.13.0, 8.4.2, 8.4.3, 7.7.0, 8.4.4, 8.4.5, 8.5.0, 8.5.1, 7.8.0, 8.5.2, 8.5.3, 7.8.1, 8.5.4, 8.5.5, 8.6.0, 8.6.1, 6.13.1, 8.6.2, 6.13.2, 8.6.3, 6.13.3, 7.8.2, 8.6.4, 8.7.0, 8.7.1, 8.7.2, 8.7.3]
Recommendation: update mongoose to 4.3.6 or higher

890 Other Versions

Version License Security Released
6.12.4 MIT 2023-12-27 - 20:39 10 months
6.12.3 MIT 2023-11-07 - 18:04 12 months
6.12.2 MIT 2023-10-25 - 18:21 about 1 year
6.12.1 MIT 2023-10-12 - 17:41 about 1 year
6.12.0 MIT 2023-08-24 - 19:58 about 1 year
6.11.6 MIT 2023-08-21 - 14:14 about 1 year
6.11.5 MIT 2023-08-01 - 19:17 about 1 year
6.11.4 MIT 2023-07-17 - 20:25 over 1 year
6.11.3 MIT 2023-07-11 - 21:01 over 1 year
6.11.2 MIT 1 2023-06-08 - 12:24 over 1 year
6.11.1 MIT 1 2023-05-08 - 17:49 over 1 year
6.11.0 MIT 1 2023-05-01 - 19:40 over 1 year
6.10.5 MIT 1 2023-04-06 - 18:20 over 1 year
6.10.4 MIT 1 2023-03-21 - 13:52 over 1 year
6.10.3 MIT 1 2023-03-13 - 14:57 over 1 year
6.10.2 MIT 1 2023-03-07 - 20:47 over 1 year
6.10.1 MIT 1 2023-03-03 - 16:49 over 1 year
6.10.0 MIT 1 2023-02-22 - 21:59 over 1 year
6.9.3 MIT 1 2023-02-22 - 15:28 over 1 year
6.9.2 MIT 1 2023-02-16 - 21:58 over 1 year
6.9.1 MIT 1 2023-02-06 - 21:31 over 1 year
6.9.0 MIT 1 2023-01-25 - 19:37 almost 2 years
6.8.4 MIT 1 2023-01-17 - 16:50 almost 2 years
6.8.3 MIT 1 2023-01-06 - 17:41 almost 2 years
6.8.2 MIT 1 2022-12-28 - 17:37 almost 2 years
6.8.1 MIT 1 2022-12-19 - 22:23 almost 2 years
6.8.0 MIT 1 2022-12-05 - 18:22 almost 2 years
6.7.5 MIT 1 2022-11-30 - 17:59 almost 2 years
6.7.4 MIT 1 2022-11-28 - 18:48 almost 2 years
6.7.3 MIT 1 2022-11-22 - 21:50 almost 2 years
6.7.2 MIT 1 2022-11-07 - 17:21 almost 2 years
6.7.1 MIT 1 2022-11-02 - 16:50 almost 2 years
6.7.0 MIT 1 2022-10-24 - 20:54 about 2 years
6.6.7 MIT 1 2022-10-21 - 19:53 about 2 years
6.6.6 MIT 1 2022-10-20 - 18:04 about 2 years
6.6.5 MIT 1 2022-10-05 - 16:13 about 2 years
6.6.4 MIT 1 2022-10-03 - 16:26 about 2 years
6.6.3 MIT 1 2022-09-30 - 16:23 about 2 years
6.6.2 MIT 1 2022-09-26 - 16:24 about 2 years
6.6.1 MIT 1 2022-09-14 - 16:19 about 2 years
6.6.0 MIT 1 2022-09-08 - 19:11 about 2 years
6.5.5 MIT 1 2022-09-07 - 17:23 about 2 years
6.5.4 MIT 1 2022-08-30 - 19:10 about 2 years
6.5.3 MIT 1 2022-08-25 - 01:29 about 2 years
6.5.2 MIT 1 2022-08-10 - 00:58 about 2 years
6.5.1 MIT 1 2022-08-03 - 19:56 about 2 years
6.5.0 MIT 1 2022-07-26 - 22:36 over 2 years
6.4.7 MIT 1 2022-07-25 - 21:18 over 2 years
6.4.6 MIT 1 2022-07-20 - 17:28 over 2 years
6.4.5 MIT 3 2022-07-18 - 16:00 over 2 years
6.4.4 MIT 3 2022-07-08 - 15:28 over 2 years
6.4.3 MIT 3 2022-07-05 - 14:54 over 2 years
6.4.2 MIT 3 2022-07-01 - 19:34 over 2 years
6.4.1 MIT 3 2022-06-27 - 18:15 over 2 years
6.4.0 MIT 3 2022-06-17 - 19:46 over 2 years
6.3.9 MIT 3 2022-06-17 - 19:08 over 2 years
6.3.8 MIT 3 2022-06-13 - 18:09 over 2 years
6.3.7 MIT 3 2022-06-13 - 17:52 over 2 years
6.3.6 MIT 3 2022-06-07 - 16:54 over 2 years
6.3.5 MIT 3 2022-05-30 - 20:32 over 2 years
6.3.4 MIT 3 2022-05-19 - 18:56 over 2 years
6.3.3 MIT 3 2022-05-09 - 16:24 over 2 years
6.3.2 MIT 3 2022-05-02 - 16:21 over 2 years
6.3.1 MIT 3 2022-04-21 - 22:05 over 2 years
6.3.0 MIT 3 2022-04-14 - 17:03 over 2 years
6.2.11 MIT 3 2022-04-13 - 17:03 over 2 years
6.2.10 MIT 3 2022-04-04 - 19:50 over 2 years
6.2.9 MIT 3 2022-03-28 - 16:37 over 2 years
6.2.8 MIT 3 2022-03-23 - 01:55 over 2 years
6.2.7 MIT 3 2022-03-16 - 16:24 over 2 years
6.2.6 MIT 3 2022-03-11 - 22:39 over 2 years
6.2.5 MIT 3 2022-03-09 - 17:00 over 2 years
6.2.4 MIT 3 2022-02-28 - 22:06 over 2 years
6.2.3 MIT 3 2022-02-21 - 19:10 over 2 years
6.2.2 MIT 3 2022-02-16 - 21:32 over 2 years
6.2.1 MIT 3 2022-02-07 - 22:06 over 2 years
6.2.0 MIT 3 2022-02-02 - 18:37 over 2 years
6.1.10 MIT 3 2022-02-01 - 18:20 over 2 years
6.1.9 MIT 3 2022-01-31 - 17:02 over 2 years
6.1.8 MIT 3 2022-01-24 - 19:25 almost 3 years
6.1.7 MIT 3 2022-01-17 - 16:00 almost 3 years
6.1.6 MIT 3 2022-01-10 - 16:44 almost 3 years
6.1.5 MIT 3 2022-01-04 - 16:54 almost 3 years
6.1.4 MIT 3 2021-12-27 - 18:30 almost 3 years
6.1.3 MIT 3 2021-12-21 - 19:17 almost 3 years
6.1.2 MIT 3 2021-12-15 - 00:03 almost 3 years
6.1.1 MIT 3 2021-12-09 - 17:28 almost 3 years
6.1.0 MIT 3 2021-12-07 - 17:46 almost 3 years
6.0.15 MIT 3 2021-12-06 - 21:50 almost 3 years
6.0.14 MIT 3 2021-11-29 - 22:11 almost 3 years
6.0.13 MIT 3 2021-11-15 - 19:00 almost 3 years
6.0.12 MIT 3 2021-10-21 - 21:19 about 3 years
6.0.11 MIT 3 2021-10-14 - 22:02 about 3 years
6.0.10 MIT 3 2021-10-08 - 15:14 about 3 years
6.0.9 MIT 3 2021-10-04 - 20:26 about 3 years
6.0.8 MIT 3 2021-09-27 - 14:41 about 3 years
6.0.7 MIT 3 2021-09-20 - 18:45 about 3 years
6.0.6 MIT 3 2021-09-15 - 16:33 about 3 years
6.0.5 MIT 3 2021-09-06 - 18:23 about 3 years
6.0.4 MIT 3 2021-09-01 - 21:11 about 3 years