NodeJS/mongoose/4.3.3


Mongoose MongoDB ODM

https://www.npmjs.com/package/mongoose
MIT

5 Security Vulnerabilities

Improper Input Validation in Automattic Mongoose

Published date: 2019-10-22T20:19:54Z
CVE: CVE-2019-17426
Links:

Automattic Mongoose through 5.7.4 allows attackers to bypass access control (in some applications) because any query object with a _bsontype attribute is ignored. For example, adding "_bsontype":"a" can sometimes interfere with a query filter. NOTE: this CVE is about Mongoose's failure to work around this _bsontype special case that exists in older versions of the bson parser (aka the mongodb/js-bson project).

Affected versions: ["0.0.1", "0.0.2", "0.0.3", "0.0.4", "0.0.5", "1.0.0", "1.0.1", "1.0.2", "0.0.6", "1.0.3", "1.0.4", "1.0.5", "1.0.6", "1.0.7", "1.0.8", "1.0.10", "1.0.11", "1.0.12", "1.0.13", "1.0.14", "1.0.15", "1.0.16", "1.1.0", "1.1.1", "1.1.2", "1.1.3", "1.1.4", "1.1.5", "1.1.6", "1.1.7", "1.1.8", "1.1.9", "1.1.10", "1.1.11", "1.1.12", "1.1.13", "1.1.14", "1.1.15", "1.1.16", "1.1.17", "1.1.18", "1.1.19", "1.1.20", "1.1.21", "1.1.22", "1.1.23", "1.1.24", "1.1.25", "1.2.0", "1.3.0", "1.3.1", "1.3.2", "1.3.3", "1.3.4", "1.3.5", "1.3.6", "1.3.7", "1.4.0", "1.5.0", "1.6.0", "1.7.2", "1.7.3", "1.7.4", "1.8.0", "1.8.1", "1.8.2", "1.8.3", "1.8.4", "2.0.0", "2.0.1", "2.0.2", "2.0.3", "2.0.4", "2.1.0", "2.1.1", "2.1.2", "2.1.3", "2.1.4", "2.2.0", "2.2.1", "2.2.2", "2.2.3", "2.2.4", "2.3.0", "2.3.1", "2.3.2", "2.3.3", "2.3.4", "2.3.5", "2.3.6", "2.3.7", "2.3.8", "2.3.9", "2.3.10", "2.3.11", "2.3.12", "2.3.13", "2.4.0", "2.4.1", "2.4.2", "2.4.3", "2.4.4", "2.4.5", "2.4.6", "2.4.7", "2.4.8", "2.4.9", "2.4.10", "2.5.0", "2.5.1", "2.5.2", "2.5.3", "2.5.4", "2.5.5", "2.5.6", "2.5.7", "2.5.8", "2.5.9", "2.5.10", "2.5.11", "2.5.12", "2.5.13", "2.5.14", "2.6.0", "2.6.1", "2.6.2", "2.6.3", "2.6.4", "2.6.5", "2.6.6", "2.6.7", "2.6.8", "2.7.0", "2.7.1", "2.7.2", "2.7.4", "2.7.3", "3.0.0", "3.0.1", "3.0.2", "2.8.0", "3.0.3", "3.1.0", "2.8.1", "3.1.1", "2.8.2", "2.8.3", "2.9.0", "3.2.0", "2.9.1", "3.2.1", "2.9.2", "3.2.2", "3.3.0", "3.3.1", "2.9.3", "3.4.0", "2.9.4", "2.9.5", "3.5.0", "3.5.1", "3.5.2", "3.5.3", "2.9.6", "2.9.7", "3.5.4", "3.5.5", "2.9.8", "2.9.9", "3.5.6", "3.5.7", "3.5.8", "2.9.10", "3.5.9", "3.6.2", "3.5.10", "3.6.3", "3.5.11", "3.6.4", "3.6.5", "3.6.6", "3.6.7", "3.5.12", "3.6.8", "3.6.9", "3.6.10", "3.5.13", "3.5.14", "3.6.11", "3.6.12", "3.6.13", "3.6.14", "3.6.15", "3.5.15", "3.7.0", "3.6.16", "3.5.16", "3.6.17", "3.7.2", "3.0.0-alpha1", "3.0.0-alpha2", "3.0.0-rc0", "3.6.0-rc0", "3.6.0-rc1", "3.6.18", "3.7.3", "3.6.19", "3.6.20", "3.7.4", "3.8.0", "3.8.1", "3.8.2", "3.8.3", "3.8.4", "3.8.5", "3.8.6", "3.8.7", "3.8.8", "3.8.9", "3.8.10", "3.8.11", "3.9.0", "3.8.12", "3.8.13", "3.8.14", "3.8.15", "3.9.1", "3.8.16", "3.9.2", "3.8.17", "3.9.3", "3.8.18", "3.9.4", "3.8.19", "3.9.5", "3.8.20", "3.9.6", "3.8.21", "3.9.7", "3.8.22", "4.0.0-rc0", "4.0.0-rc1", "3.8.23", "4.0.0-rc2", "3.8.24", "4.0.0-rc3", "3.8.25", "4.0.0-rc4", "4.0.0", "4.0.1", "3.8.26", "3.8.27", "4.0.2", "3.8.28", "4.0.3", "3.8.29", "4.0.4", "3.8.30", "4.0.5", "3.8.31", "4.0.6", "3.8.33", "4.0.7", "3.8.34", "4.0.8", "4.1.0", "4.1.1", "4.1.2", "3.8.35", "4.1.3", "4.1.5", "4.1.6", "4.1.7", "4.1.8", "4.1.9", "4.1.10", "4.1.11", "3.8.36", "4.1.12", "4.2.0", "4.2.1", "4.2.2", "4.2.3", "4.2.4", "4.2.5", "3.8.37", "4.2.6", "4.2.7", "4.2.8", "4.2.9", "4.2.10", "4.3.0", "4.3.1", "4.3.2", "4.3.3", "4.3.4", "3.8.38", "4.3.5", "4.3.6", "3.8.39", "4.3.7", "4.4.0", "4.4.1", "4.4.2", "4.4.3", "4.4.4", "4.4.5", "4.4.6", "4.4.7", "4.4.8", "4.4.9", "4.4.10", "4.4.11", "4.4.12", "4.4.13", "3.8.40", "4.4.14", "4.4.15", "4.4.16", "4.4.17", "4.4.18", "4.4.19", "4.4.20", "4.5.0", "4.5.1", "4.5.2", "4.5.3", "4.5.4", "4.5.5", "4.5.6", "4.5.7", "4.5.8", "4.5.9", "4.5.10", "4.6.0", "4.6.1", "4.6.2", "4.6.3", "4.6.4", "4.6.5", "4.6.6", "4.6.7", "4.6.8", "4.7.0", "4.7.1", "4.7.2", "4.7.3", "4.7.4", "4.7.5-pre", "4.7.5", "4.7.6", "4.7.7", "4.7.8", "4.7.9", "4.8.0", "4.8.1", "4.8.2", "4.8.3", "4.8.4", "4.8.5", "4.8.6", "4.8.7", "4.9.0", "4.9.1", "4.9.2", "4.9.3", "4.9.4", "4.9.5", "4.9.6", "4.9.7", "4.9.8", "4.9.9", "4.9.10", "4.10.0", "4.10.1", "4.10.2", "4.10.3", "4.10.4", "4.10.5", "4.10.6", "4.10.7", "4.10.8", "4.11.0", "4.11.1", "4.11.2", "4.11.3", "4.11.4", "4.11.5", "4.11.6", "4.11.7", "4.11.8", "4.11.9", "4.11.10", "4.11.11", "4.11.12", "4.11.13", "4.11.14", "4.12.0", "4.12.1", "4.12.2", "4.12.3", "4.12.4", "4.12.5", "4.12.6", "4.13.0", "4.13.1", "4.13.2", "4.13.3", "4.13.4", "4.13.5", "4.13.6", "4.13.7", "4.13.8", "4.13.9", "4.13.10", "4.13.11", "4.13.12", "4.13.13", "4.13.14", "4.13.15", "4.13.16", "4.13.17", "4.13.18", "4.13.19", "4.13.20", "5.0.0", "5.0.1", "5.0.2", "5.0.3", "5.0.4", "5.0.5", "5.0.6", "5.0.7", "5.0.8", "5.0.9", "5.0.10", "5.0.11", "5.0.12", "5.0.13", "5.0.14", "5.0.15", "5.0.16", "5.0.17", "5.0.18", "5.1.0", "5.1.1", "5.1.2", "5.1.3", "5.1.4", "5.1.5", "5.1.6", "5.1.7", "5.1.8", "5.2.0", "5.2.1", "5.2.2", "5.2.3", "5.2.4", "5.2.5", "5.2.6", "5.2.7", "5.2.8", "5.2.9", "5.2.10", "5.2.11", "5.2.12", "5.2.13", "5.2.14", "5.2.15", "5.2.16", "5.2.17", "5.2.18", "5.3.0", "5.3.1", "5.3.2", "5.3.3", "5.3.4", "5.3.5", "5.3.6", "5.3.7", "5.3.8", "5.3.9", "5.3.10", "5.3.11", "5.3.12", "5.3.13", "5.3.14", "5.3.15", "5.3.16", "5.4.0", "5.4.1", "5.4.2", "5.4.3", "5.4.4", "5.4.5", "5.4.6", "5.4.7", "5.4.8", "5.4.9", "5.4.10", "5.4.11", "5.4.12", "5.4.13", "5.4.14", "5.4.15", "5.4.16", "5.4.17", "5.4.18", "5.4.19", "5.4.20", "5.4.21", "5.4.22", "5.4.23", "5.5.0", "5.5.1", "5.5.2", "5.5.3", "5.5.4", "5.5.5", "5.5.6", "5.5.7", "5.5.8", "5.5.9", "5.5.10", "5.5.11", "5.5.12", "5.5.13", "5.5.14", "5.5.15", "5.6.0", "5.6.1", "5.6.2", "5.6.3", "5.6.4", "5.6.5", "5.6.6", "5.6.7", "5.6.8", "5.6.9", "5.6.10", "5.6.11", "5.6.12", "5.6.13", "5.7.0", "5.7.1", "5.7.3", "5.7.4"]
Secure versions: [6.0.0-rc0, 6.0.0-rc1, 6.0.0-rc2, 7.0.0-rc0, 7.3.3, 6.11.3, 5.13.20, 7.3.4, 6.11.4, 7.4.0, 7.4.1, 6.11.5, 7.4.2, 7.4.3, 6.11.6, 7.4.4, 6.12.0, 7.4.5, 7.5.0, 7.5.1, 7.5.2, 7.5.3, 7.5.4, 7.6.0, 7.6.1, 6.12.1, 7.6.2, 7.6.3, 5.13.21, 8.0.0-rc0, 6.12.2, 7.6.4, 8.0.0, 6.12.3, 7.6.5, 8.0.1, 7.6.6, 8.0.2, 7.6.7, 8.0.3, 6.12.4, 5.13.22, 6.12.5, 7.6.8, 8.0.4, 8.1.0, 6.12.6, 8.1.1, 8.1.2, 8.1.3, 8.2.0, 7.6.9, 6.12.7, 8.2.1, 7.6.10, 8.2.2, 8.2.3, 8.2.4, 8.3.0, 8.3.1, 6.12.8, 7.6.11, 8.3.2, 8.3.3, 8.3.4, 8.3.5, 8.4.0, 7.6.12, 6.12.9, 8.4.1, 7.6.13, 6.13.0, 8.4.2, 8.4.3, 7.7.0, 8.4.4, 8.4.5, 8.5.0, 8.5.1, 7.8.0, 8.5.2, 8.5.3, 7.8.1, 8.5.4, 8.5.5, 8.6.0, 8.6.1, 6.13.1, 8.6.2, 6.13.2, 8.6.3, 6.13.3, 7.8.2, 8.6.4, 8.7.0, 8.7.1, 8.7.2, 8.7.3]
Recommendation: Update to version 8.7.3.

Mongoose Prototype Pollution vulnerability

Published date: 2023-07-17T03:30:20Z
CVE: CVE-2023-3696
Links:

Prototype Pollution in GitHub repository automattic/mongoose prior to 7.3.3, 6.11.3, and 5.13.20.

Affected versions: ["0.0.1", "0.0.2", "0.0.3", "0.0.4", "0.0.5", "1.0.0", "1.0.1", "1.0.2", "0.0.6", "1.0.3", "1.0.4", "1.0.5", "1.0.6", "1.0.7", "1.0.8", "1.0.10", "1.0.11", "1.0.12", "1.0.13", "1.0.14", "1.0.15", "1.0.16", "1.1.0", "1.1.1", "1.1.2", "1.1.3", "1.1.4", "1.1.5", "1.1.6", "1.1.7", "1.1.8", "1.1.9", "1.1.10", "1.1.11", "1.1.12", "1.1.13", "1.1.14", "1.1.15", "1.1.16", "1.1.17", "1.1.18", "1.1.19", "1.1.20", "1.1.21", "1.1.22", "1.1.23", "1.1.24", "1.1.25", "1.2.0", "1.3.0", "1.3.1", "1.3.2", "1.3.3", "1.3.4", "1.3.5", "1.3.6", "1.3.7", "1.4.0", "1.5.0", "1.6.0", "1.7.2", "1.7.3", "1.7.4", "1.8.0", "1.8.1", "1.8.2", "1.8.3", "1.8.4", "2.0.0", "2.0.1", "2.0.2", "2.0.3", "2.0.4", "2.1.0", "2.1.1", "2.1.2", "2.1.3", "2.1.4", "2.2.0", "2.2.1", "2.2.2", "2.2.3", "2.2.4", "2.3.0", "2.3.1", "2.3.2", "2.3.3", "2.3.4", "2.3.5", "2.3.6", "2.3.7", "2.3.8", "2.3.9", "2.3.10", "2.3.11", "2.3.12", "2.3.13", "2.4.0", "2.4.1", "2.4.2", "2.4.3", "2.4.4", "2.4.5", "2.4.6", "2.4.7", "2.4.8", "2.4.9", "2.4.10", "2.5.0", "2.5.1", "2.5.2", "2.5.3", "2.5.4", "2.5.5", "2.5.6", "2.5.7", "2.5.8", "2.5.9", "2.5.10", "2.5.11", "2.5.12", "2.5.13", "2.5.14", "2.6.0", "2.6.1", "2.6.2", "2.6.3", "2.6.4", "2.6.5", "2.6.6", "2.6.7", "2.6.8", "2.7.0", "2.7.1", "2.7.2", "2.7.4", "2.7.3", "3.0.0", "3.0.1", "3.0.2", "2.8.0", "3.0.3", "3.1.0", "2.8.1", "3.1.1", "2.8.2", "2.8.3", "2.9.0", "3.2.0", "2.9.1", "3.2.1", "2.9.2", "3.2.2", "3.3.0", "3.3.1", "2.9.3", "3.4.0", "2.9.4", "2.9.5", "3.5.0", "3.5.1", "3.5.2", "3.5.3", "2.9.6", "2.9.7", "3.5.4", "3.5.5", "2.9.8", "2.9.9", "3.5.6", "3.5.7", "3.5.8", "2.9.10", "3.5.9", "3.6.2", "3.5.10", "3.6.3", "3.5.11", "3.6.4", "3.6.5", "3.6.6", "3.6.7", "3.5.12", "3.6.8", "3.6.9", "3.6.10", "3.5.13", "3.5.14", "3.6.11", "3.6.12", "3.6.13", "3.6.14", "3.6.15", "3.5.15", "3.7.0", "3.6.16", "3.5.16", "3.6.17", "3.7.2", "3.0.0-alpha1", "3.0.0-alpha2", "3.0.0-rc0", "3.6.0-rc0", "3.6.0-rc1", "3.6.18", "3.7.3", "3.6.19", "3.6.20", "3.7.4", "3.8.0", "3.8.1", "3.8.2", "3.8.3", "3.8.4", "3.8.5", "3.8.6", "3.8.7", "3.8.8", "3.8.9", "3.8.10", "3.8.11", "3.9.0", "3.8.12", "3.8.13", "3.8.14", "3.8.15", "3.9.1", "3.8.16", "3.9.2", "3.8.17", "3.9.3", "3.8.18", "3.9.4", "3.8.19", "3.9.5", "3.8.20", "3.9.6", "3.8.21", "3.9.7", "3.8.22", "4.0.0-rc0", "4.0.0-rc1", "3.8.23", "4.0.0-rc2", "3.8.24", "4.0.0-rc3", "3.8.25", "4.0.0-rc4", "4.0.0", "4.0.1", "3.8.26", "3.8.27", "4.0.2", "3.8.28", "4.0.3", "3.8.29", "4.0.4", "3.8.30", "4.0.5", "3.8.31", "4.0.6", "3.8.33", "4.0.7", "3.8.34", "4.0.8", "4.1.0", "4.1.1", "4.1.2", "3.8.35", "4.1.3", "4.1.5", "4.1.6", "4.1.7", "4.1.8", "4.1.9", "4.1.10", "4.1.11", "3.8.36", "4.1.12", "4.2.0", "4.2.1", "4.2.2", "4.2.3", "4.2.4", "4.2.5", "3.8.37", "4.2.6", "4.2.7", "4.2.8", "4.2.9", "4.2.10", "4.3.0", "4.3.1", "4.3.2", "4.3.3", "4.3.4", "3.8.38", "4.3.5", "4.3.6", "3.8.39", "4.3.7", "4.4.0", "4.4.1", "4.4.2", "4.4.3", "4.4.4", "4.4.5", "4.4.6", "4.4.7", "4.4.8", "4.4.9", "4.4.10", "4.4.11", "4.4.12", "4.4.13", "3.8.40", "4.4.14", "4.4.15", "4.4.16", "4.4.17", "4.4.18", "4.4.19", "4.4.20", "4.5.0", "4.5.1", "4.5.2", "4.5.3", "4.5.4", "4.5.5", "4.5.6", "4.5.7", "4.5.8", "4.5.9", "4.5.10", "4.6.0", "4.6.1", "4.6.2", "4.6.3", "4.6.4", "4.6.5", "4.6.6", "4.6.7", "4.6.8", "4.7.0", "4.7.1", "4.7.2", "4.7.3", "4.7.4", "4.7.5-pre", "4.7.5", "4.7.6", "4.7.7", "4.7.8", "4.7.9", "4.8.0", "4.8.1", "4.8.2", "4.8.3", "4.8.4", "4.8.5", "4.8.6", "4.8.7", "4.9.0", "4.9.1", "4.9.2", "4.9.3", "4.9.4", "4.9.5", "4.9.6", "4.9.7", "4.9.8", "4.9.9", "4.9.10", "4.10.0", "4.10.1", "4.10.2", "4.10.3", "4.10.4", "4.10.5", "4.10.6", "4.10.7", "4.10.8", "4.11.0", "4.11.1", "4.11.2", "4.11.3", "4.11.4", "4.11.5", "4.11.6", "4.11.7", "4.11.8", "4.11.9", "4.11.10", "4.11.11", "4.11.12", "4.11.13", "4.11.14", "4.12.0", "4.12.1", "4.12.2", "4.12.3", "4.12.4", "4.12.5", "4.12.6", "4.13.0", "4.13.1", "4.13.2", "4.13.3", "4.13.4", "4.13.5", "4.13.6", "4.13.7", "4.13.8", "5.0.0-rc0", "5.0.0-rc1", "5.0.0-rc2", "4.13.9", "5.0.0", "5.0.1", "4.13.10", "5.0.2", "5.0.3", "4.13.11", "5.0.4", "5.0.5", "5.0.6", "5.0.7", "5.0.8", "5.0.9", "5.0.10", "4.13.12", "5.0.11", "5.0.12", "5.0.13", "5.0.14", "5.0.15", "5.0.16", "5.0.17", "5.0.18", "5.1.0", "5.1.1", "4.13.13", "5.1.2", "4.13.14", "5.1.3", "5.1.4", "5.1.5", "5.1.6", "5.1.7", "5.1.8", "5.2.0", "5.2.1", "5.2.2", "5.2.3", "5.2.4", "5.2.5", "5.2.6", "5.2.7", "5.2.8", "4.13.15", "5.2.9", "5.2.10", "4.13.16", "5.2.11", "4.13.17", "5.2.12", "5.2.13", "5.2.14", "5.2.15", "5.2.16", "5.2.17", "5.2.18", "5.3.0", "5.3.1", "5.3.2", "5.3.3", "5.3.4", "5.3.5", "5.3.6", "5.3.7", "5.3.8", "5.3.9", "5.3.10", "5.3.11", "5.3.12", "5.3.13", "5.3.14", "5.3.15", "5.3.16", "5.4.0", "5.4.1", "5.4.2", "5.4.3", "5.4.4", "5.4.5", "4.13.18", "5.4.6", "5.4.7", "5.4.8", "5.4.9", "5.4.10", "5.4.11", "5.4.12", "5.4.13", "5.4.14", "5.4.15", "5.4.16", "5.4.17", "5.4.18", "5.4.19", "5.4.20", "5.4.21", "5.4.22", "5.4.23", "5.5.0", "5.5.1", "5.5.2", "5.5.3", "5.5.4", "5.5.5", "5.5.6", "5.5.7", "5.5.8", "5.5.9", "5.5.10", "5.5.11", "5.5.12", "5.5.13", "5.5.14", "5.5.15", "5.6.0", "5.6.1", "5.6.2", "5.6.3", "5.6.4", "5.6.5", "4.13.19", "5.6.6", "5.6.7", "5.6.8", "5.6.9", "5.6.10", "5.6.11", "5.6.12", "5.6.13", "5.7.0", "5.7.1", "5.7.3", "5.7.4", "5.7.5", "5.7.6", "5.7.7", "5.7.8", "5.7.9", "5.7.10", "5.7.11", "5.7.12", "5.7.13", "5.7.14", "5.8.0", "5.8.1", "5.8.2", "5.8.3", "5.8.4", "5.8.5", "4.13.20", "5.8.6", "5.8.7", "5.8.9", "5.8.10", "5.8.11", "5.8.12", "5.8.13", "5.9.0", "5.9.1", "5.9.2", "5.9.3", "5.9.4", "5.9.5", "5.9.6", "5.9.7", "5.9.9", "5.9.10", "5.9.11", "5.9.12", "5.9.13", "5.9.14", "5.9.15", "5.9.16", "5.9.17", "5.9.18", "5.9.19", "5.9.20", "5.9.21", "5.9.22", "5.9.23", "4.13.21", "5.9.24", "5.9.25", "5.9.26", "5.9.27", "5.9.28", "5.9.29", "5.10.0", "5.10.1", "5.10.2", "5.10.3", "5.10.4", "5.10.5", "5.10.6", "5.10.7", "5.10.8", "5.10.9", "5.10.10", "5.10.11", "5.10.12", "5.10.13", "5.10.14", "5.10.15", "5.10.16", "5.10.17", "5.10.18", "5.10.19", "5.11.0", "5.11.1", "5.11.2", "5.11.3", "5.11.4", "5.11.5", "5.11.6", "5.11.7", "5.11.8", "5.11.9", "5.11.10", "5.11.11", "5.11.12", "5.11.13", "5.11.14", "5.11.15", "5.11.16", "5.11.17", "5.11.18", "5.11.19", "5.11.20", "5.12.0", "5.12.1", "5.12.2", "5.12.3", "5.12.4", "5.12.5", "5.12.6", "5.12.7", "5.12.8", "5.12.9", "5.12.10", "5.12.11", "5.12.12", "5.12.13", "5.12.14", "5.12.15", "5.13.0", "5.13.1", "5.13.2", "5.13.3", "5.13.4", "5.13.5", "5.13.6", "5.13.7", "5.13.8", "5.13.9", "5.13.10", "5.13.11", "5.13.12", "5.13.13", "5.13.14", "5.13.15", "5.13.16", "5.13.17", "5.13.18", "5.13.19", "6.0.0", "6.0.1", "6.0.2", "6.0.3", "6.0.4", "6.0.5", "6.0.6", "6.0.7", "6.0.8", "6.0.9", "6.0.10", "6.0.11", "6.0.12", "6.0.13", "6.0.14", "6.0.15", "6.1.0", "6.1.1", "6.1.2", "6.1.3", "6.1.4", "6.1.5", "6.1.6", "6.1.7", "6.1.8", "6.1.9", "6.1.10", "6.2.0", "6.2.1", "6.2.2", "6.2.3", "6.2.4", "6.2.5", "6.2.6", "6.2.7", "6.2.8", "6.2.9", "6.2.10", "6.2.11", "6.3.0", "6.3.1", "6.3.2", "6.3.3", "6.3.4", "6.3.5", "6.3.6", "6.3.7", "6.3.8", "6.3.9", "6.4.0", "6.4.1", "6.4.2", "6.4.3", "6.4.4", "6.4.5", "6.4.6", "6.4.7", "6.5.0", "6.5.1", "6.5.2", "6.5.3", "6.5.4", "6.5.5", "6.6.0", "6.6.1", "6.6.2", "6.6.3", "6.6.4", "6.6.5", "6.6.6", "6.6.7", "6.7.0", "6.7.1", "6.7.2", "6.7.3", "6.7.4", "6.7.5", "6.8.0", "6.8.1", "6.8.2", "6.8.3", "6.8.4", "6.9.0", "6.9.1", "6.9.2", "6.9.3", "6.10.0", "6.10.1", "6.10.2", "6.10.3", "6.10.4", "6.10.5", "6.11.0", "6.11.1", "6.11.2", "7.0.0", "7.0.1", "7.0.2", "7.0.3", "7.0.4", "7.0.5", "7.1.0", "7.1.1", "7.1.2", "7.2.0", "7.2.1", "7.2.2", "7.2.3", "7.2.4", "7.3.0", "7.3.1", "7.3.2"]
Secure versions: [6.0.0-rc0, 6.0.0-rc1, 6.0.0-rc2, 7.0.0-rc0, 7.3.3, 6.11.3, 5.13.20, 7.3.4, 6.11.4, 7.4.0, 7.4.1, 6.11.5, 7.4.2, 7.4.3, 6.11.6, 7.4.4, 6.12.0, 7.4.5, 7.5.0, 7.5.1, 7.5.2, 7.5.3, 7.5.4, 7.6.0, 7.6.1, 6.12.1, 7.6.2, 7.6.3, 5.13.21, 8.0.0-rc0, 6.12.2, 7.6.4, 8.0.0, 6.12.3, 7.6.5, 8.0.1, 7.6.6, 8.0.2, 7.6.7, 8.0.3, 6.12.4, 5.13.22, 6.12.5, 7.6.8, 8.0.4, 8.1.0, 6.12.6, 8.1.1, 8.1.2, 8.1.3, 8.2.0, 7.6.9, 6.12.7, 8.2.1, 7.6.10, 8.2.2, 8.2.3, 8.2.4, 8.3.0, 8.3.1, 6.12.8, 7.6.11, 8.3.2, 8.3.3, 8.3.4, 8.3.5, 8.4.0, 7.6.12, 6.12.9, 8.4.1, 7.6.13, 6.13.0, 8.4.2, 8.4.3, 7.7.0, 8.4.4, 8.4.5, 8.5.0, 8.5.1, 7.8.0, 8.5.2, 8.5.3, 7.8.1, 8.5.4, 8.5.5, 8.6.0, 8.6.1, 6.13.1, 8.6.2, 6.13.2, 8.6.3, 6.13.3, 7.8.2, 8.6.4, 8.7.0, 8.7.1, 8.7.2, 8.7.3]
Recommendation: Update to version 8.7.3.

automattic/mongoose vulnerable to Prototype pollution via Schema.path

Published date: 2022-07-29T00:00:18Z
CVE: CVE-2022-2564
Links:

Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Affected versions of this package are vulnerable to Prototype Pollution. The Schema.path() function is vulnerable to prototype pollution when setting the schema object. This vulnerability allows modification of the Object prototype and could be manipulated into a Denial of Service (DoS) attack.

Affected versions: ["0.0.1", "0.0.2", "0.0.3", "0.0.4", "0.0.5", "1.0.0", "1.0.1", "1.0.2", "0.0.6", "1.0.3", "1.0.4", "1.0.5", "1.0.6", "1.0.7", "1.0.8", "1.0.10", "1.0.11", "1.0.12", "1.0.13", "1.0.14", "1.0.15", "1.0.16", "1.1.0", "1.1.1", "1.1.2", "1.1.3", "1.1.4", "1.1.5", "1.1.6", "1.1.7", "1.1.8", "1.1.9", "1.1.10", "1.1.11", "1.1.12", "1.1.13", "1.1.14", "1.1.15", "1.1.16", "1.1.17", "1.1.18", "1.1.19", "1.1.20", "1.1.21", "1.1.22", "1.1.23", "1.1.24", "1.1.25", "1.2.0", "1.3.0", "1.3.1", "1.3.2", "1.3.3", "1.3.4", "1.3.5", "1.3.6", "1.3.7", "1.4.0", "1.5.0", "1.6.0", "1.7.2", "1.7.3", "1.7.4", "1.8.0", "1.8.1", "1.8.2", "1.8.3", "1.8.4", "2.0.0", "2.0.1", "2.0.2", "2.0.3", "2.0.4", "2.1.0", "2.1.1", "2.1.2", "2.1.3", "2.1.4", "2.2.0", "2.2.1", "2.2.2", "2.2.3", "2.2.4", "2.3.0", "2.3.1", "2.3.2", "2.3.3", "2.3.4", "2.3.5", "2.3.6", "2.3.7", "2.3.8", "2.3.9", "2.3.10", "2.3.11", "2.3.12", "2.3.13", "2.4.0", "2.4.1", "2.4.2", "2.4.3", "2.4.4", "2.4.5", "2.4.6", "2.4.7", "2.4.8", "2.4.9", "2.4.10", "2.5.0", "2.5.1", "2.5.2", "2.5.3", "2.5.4", "2.5.5", "2.5.6", "2.5.7", "2.5.8", "2.5.9", "2.5.10", "2.5.11", "2.5.12", "2.5.13", "2.5.14", "2.6.0", "2.6.1", "2.6.2", "2.6.3", "2.6.4", "2.6.5", "2.6.6", "2.6.7", "2.6.8", "2.7.0", "2.7.1", "2.7.2", "2.7.4", "2.7.3", "3.0.0", "3.0.1", "3.0.2", "2.8.0", "3.0.3", "3.1.0", "2.8.1", "3.1.1", "2.8.2", "2.8.3", "2.9.0", "3.2.0", "2.9.1", "3.2.1", "2.9.2", "3.2.2", "3.3.0", "3.3.1", "2.9.3", "3.4.0", "2.9.4", "2.9.5", "3.5.0", "3.5.1", "3.5.2", "3.5.3", "2.9.6", "2.9.7", "3.5.4", "3.5.5", "2.9.8", "2.9.9", "3.5.6", "3.5.7", "3.5.8", "2.9.10", "3.5.9", "3.6.2", "3.5.10", "3.6.3", "3.5.11", "3.6.4", "3.6.5", "3.6.6", "3.6.7", "3.5.12", "3.6.8", "3.6.9", "3.6.10", "3.5.13", "3.5.14", "3.6.11", "3.6.12", "3.6.13", "3.6.14", "3.6.15", "3.5.15", "3.7.0", "3.6.16", "3.5.16", "3.6.17", "3.7.2", "3.0.0-alpha1", "3.0.0-alpha2", "3.0.0-rc0", "3.6.0-rc0", "3.6.0-rc1", "3.6.18", "3.7.3", "3.6.19", "3.6.20", "3.7.4", "3.8.0", "3.8.1", "3.8.2", "3.8.3", "3.8.4", "3.8.5", "3.8.6", "3.8.7", "3.8.8", "3.8.9", "3.8.10", "3.8.11", "3.9.0", "3.8.12", "3.8.13", "3.8.14", "3.8.15", "3.9.1", "3.8.16", "3.9.2", "3.8.17", "3.9.3", "3.8.18", "3.9.4", "3.8.19", "3.9.5", "3.8.20", "3.9.6", "3.8.21", "3.9.7", "3.8.22", "4.0.0-rc0", "4.0.0-rc1", "3.8.23", "4.0.0-rc2", "3.8.24", "4.0.0-rc3", "3.8.25", "4.0.0-rc4", "4.0.0", "4.0.1", "3.8.26", "3.8.27", "4.0.2", "3.8.28", "4.0.3", "3.8.29", "4.0.4", "3.8.30", "4.0.5", "3.8.31", "4.0.6", "3.8.33", "4.0.7", "3.8.34", "4.0.8", "4.1.0", "4.1.1", "4.1.2", "3.8.35", "4.1.3", "4.1.5", "4.1.6", "4.1.7", "4.1.8", "4.1.9", "4.1.10", "4.1.11", "3.8.36", "4.1.12", "4.2.0", "4.2.1", "4.2.2", "4.2.3", "4.2.4", "4.2.5", "3.8.37", "4.2.6", "4.2.7", "4.2.8", "4.2.9", "4.2.10", "4.3.0", "4.3.1", "4.3.2", "4.3.3", "4.3.4", "3.8.38", "4.3.5", "4.3.6", "3.8.39", "4.3.7", "4.4.0", "4.4.1", "4.4.2", "4.4.3", "4.4.4", "4.4.5", "4.4.6", "4.4.7", "4.4.8", "4.4.9", "4.4.10", "4.4.11", "4.4.12", "4.4.13", "3.8.40", "4.4.14", "4.4.15", "4.4.16", "4.4.17", "4.4.18", "4.4.19", "4.4.20", "4.5.0", "4.5.1", "4.5.2", "4.5.3", "4.5.4", "4.5.5", "4.5.6", "4.5.7", "4.5.8", "4.5.9", "4.5.10", "4.6.0", "4.6.1", "4.6.2", "4.6.3", "4.6.4", "4.6.5", "4.6.6", "4.6.7", "4.6.8", "4.7.0", "4.7.1", "4.7.2", "4.7.3", "4.7.4", "4.7.5-pre", "4.7.5", "4.7.6", "4.7.7", "4.7.8", "4.7.9", "4.8.0", "4.8.1", "4.8.2", "4.8.3", "4.8.4", "4.8.5", "4.8.6", "4.8.7", "4.9.0", "4.9.1", "4.9.2", "4.9.3", "4.9.4", "4.9.5", "4.9.6", "4.9.7", "4.9.8", "4.9.9", "4.9.10", "4.10.0", "4.10.1", "4.10.2", "4.10.3", "4.10.4", "4.10.5", "4.10.6", "4.10.7", "4.10.8", "4.11.0", "4.11.1", "4.11.2", "4.11.3", "4.11.4", "4.11.5", "4.11.6", "4.11.7", "4.11.8", "4.11.9", "4.11.10", "4.11.11", "4.11.12", "4.11.13", "4.11.14", "4.12.0", "4.12.1", "4.12.2", "4.12.3", "4.12.4", "4.12.5", "4.12.6", "4.13.0", "4.13.1", "4.13.2", "4.13.3", "4.13.4", "4.13.5", "4.13.6", "4.13.7", "4.13.8", "5.0.0-rc0", "5.0.0-rc1", "5.0.0-rc2", "4.13.9", "5.0.0", "5.0.1", "4.13.10", "5.0.2", "5.0.3", "4.13.11", "5.0.4", "5.0.5", "5.0.6", "5.0.7", "5.0.8", "5.0.9", "5.0.10", "4.13.12", "5.0.11", "5.0.12", "5.0.13", "5.0.14", "5.0.15", "5.0.16", "5.0.17", "5.0.18", "5.1.0", "5.1.1", "4.13.13", "5.1.2", "4.13.14", "5.1.3", "5.1.4", "5.1.5", "5.1.6", "5.1.7", "5.1.8", "5.2.0", "5.2.1", "5.2.2", "5.2.3", "5.2.4", "5.2.5", "5.2.6", "5.2.7", "5.2.8", "4.13.15", "5.2.9", "5.2.10", "4.13.16", "5.2.11", "4.13.17", "5.2.12", "5.2.13", "5.2.14", "5.2.15", "5.2.16", "5.2.17", "5.2.18", "5.3.0", "5.3.1", "5.3.2", "5.3.3", "5.3.4", "5.3.5", "5.3.6", "5.3.7", "5.3.8", "5.3.9", "5.3.10", "5.3.11", "5.3.12", "5.3.13", "5.3.14", "5.3.15", "5.3.16", "5.4.0", "5.4.1", "5.4.2", "5.4.3", "5.4.4", "5.4.5", "4.13.18", "5.4.6", "5.4.7", "5.4.8", "5.4.9", "5.4.10", "5.4.11", "5.4.12", "5.4.13", "5.4.14", "5.4.15", "5.4.16", "5.4.17", "5.4.18", "5.4.19", "5.4.20", "5.4.21", "5.4.22", "5.4.23", "5.5.0", "5.5.1", "5.5.2", "5.5.3", "5.5.4", "5.5.5", "5.5.6", "5.5.7", "5.5.8", "5.5.9", "5.5.10", "5.5.11", "5.5.12", "5.5.13", "5.5.14", "5.5.15", "5.6.0", "5.6.1", "5.6.2", "5.6.3", "5.6.4", "5.6.5", "4.13.19", "5.6.6", "5.6.7", "5.6.8", "5.6.9", "5.6.10", "5.6.11", "5.6.12", "5.6.13", "5.7.0", "5.7.1", "5.7.3", "5.7.4", "5.7.5", "5.7.6", "5.7.7", "5.7.8", "5.7.9", "5.7.10", "5.7.11", "5.7.12", "5.7.13", "5.7.14", "5.8.0", "5.8.1", "5.8.2", "5.8.3", "5.8.4", "5.8.5", "4.13.20", "5.8.6", "5.8.7", "5.8.9", "5.8.10", "5.8.11", "5.8.12", "5.8.13", "5.9.0", "5.9.1", "5.9.2", "5.9.3", "5.9.4", "5.9.5", "5.9.6", "5.9.7", "5.9.9", "5.9.10", "5.9.11", "5.9.12", "5.9.13", "5.9.14", "5.9.15", "5.9.16", "5.9.17", "5.9.18", "5.9.19", "5.9.20", "5.9.21", "5.9.22", "5.9.23", "4.13.21", "5.9.24", "5.9.25", "5.9.26", "5.9.27", "5.9.28", "5.9.29", "5.10.0", "5.10.1", "5.10.2", "5.10.3", "5.10.4", "5.10.5", "5.10.6", "5.10.7", "5.10.8", "5.10.9", "5.10.10", "5.10.11", "5.10.12", "5.10.13", "5.10.14", "5.10.15", "5.10.16", "5.10.17", "5.10.18", "5.10.19", "5.11.0", "5.11.1", "5.11.2", "5.11.3", "5.11.4", "5.11.5", "5.11.6", "5.11.7", "5.11.8", "5.11.9", "5.11.10", "5.11.11", "5.11.12", "5.11.13", "5.11.14", "5.11.15", "5.11.16", "5.11.17", "5.11.18", "5.11.19", "5.11.20", "5.12.0", "5.12.1", "5.12.2", "5.12.3", "5.12.4", "5.12.5", "5.12.6", "5.12.7", "5.12.8", "5.12.9", "5.12.10", "5.12.11", "5.12.12", "5.12.13", "5.12.14", "5.12.15", "5.13.0", "5.13.1", "5.13.2", "5.13.3", "5.13.4", "5.13.5", "5.13.6", "5.13.7", "5.13.8", "5.13.9", "5.13.10", "5.13.11", "5.13.12", "5.13.13", "5.13.14", "6.0.0", "6.0.1", "6.0.2", "6.0.3", "6.0.4", "6.0.5", "6.0.6", "6.0.7", "6.0.8", "6.0.9", "6.0.10", "6.0.11", "6.0.12", "6.0.13", "6.0.14", "6.0.15", "6.1.0", "6.1.1", "6.1.2", "6.1.3", "6.1.4", "6.1.5", "6.1.6", "6.1.7", "6.1.8", "6.1.9", "6.1.10", "6.2.0", "6.2.1", "6.2.2", "6.2.3", "6.2.4", "6.2.5", "6.2.6", "6.2.7", "6.2.8", "6.2.9", "6.2.10", "6.2.11", "6.3.0", "6.3.1", "6.3.2", "6.3.3", "6.3.4", "6.3.5", "6.3.6", "6.3.7", "6.3.8", "6.3.9", "6.4.0", "6.4.1", "6.4.2", "6.4.3", "6.4.4", "6.4.5"]
Secure versions: [6.0.0-rc0, 6.0.0-rc1, 6.0.0-rc2, 7.0.0-rc0, 7.3.3, 6.11.3, 5.13.20, 7.3.4, 6.11.4, 7.4.0, 7.4.1, 6.11.5, 7.4.2, 7.4.3, 6.11.6, 7.4.4, 6.12.0, 7.4.5, 7.5.0, 7.5.1, 7.5.2, 7.5.3, 7.5.4, 7.6.0, 7.6.1, 6.12.1, 7.6.2, 7.6.3, 5.13.21, 8.0.0-rc0, 6.12.2, 7.6.4, 8.0.0, 6.12.3, 7.6.5, 8.0.1, 7.6.6, 8.0.2, 7.6.7, 8.0.3, 6.12.4, 5.13.22, 6.12.5, 7.6.8, 8.0.4, 8.1.0, 6.12.6, 8.1.1, 8.1.2, 8.1.3, 8.2.0, 7.6.9, 6.12.7, 8.2.1, 7.6.10, 8.2.2, 8.2.3, 8.2.4, 8.3.0, 8.3.1, 6.12.8, 7.6.11, 8.3.2, 8.3.3, 8.3.4, 8.3.5, 8.4.0, 7.6.12, 6.12.9, 8.4.1, 7.6.13, 6.13.0, 8.4.2, 8.4.3, 7.7.0, 8.4.4, 8.4.5, 8.5.0, 8.5.1, 7.8.0, 8.5.2, 8.5.3, 7.8.1, 8.5.4, 8.5.5, 8.6.0, 8.6.1, 6.13.1, 8.6.2, 6.13.2, 8.6.3, 6.13.3, 7.8.2, 8.6.4, 8.7.0, 8.7.1, 8.7.2, 8.7.3]
Recommendation: Update to version 8.7.3.

Mongoose Vulnerable to Prototype Pollution in Schema Object

Published date: 2022-08-27T00:00:54Z
CVE: CVE-2022-24304
Links:

Description

Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment.

Affected versions of this package are vulnerable to Prototype Pollution. The Schema.path() function is vulnerable to prototype pollution when setting the schema object. This vulnerability allows modification of the Object prototype and could be manipulated into a Denial of Service (DoS) attack.

Proof of Concept

// poc.js
const mongoose = require('mongoose');
const schema = new mongoose.Schema();

malicious_payload = '__proto__.toString'

schema.path(malicious_payload, [String])

x = {}
console.log(x.toString()) // crashed (Denial of service (DoS) attack)

Impact

This vulnerability can be manipulated to exploit other types of attacks, such as Denial of service (DoS), Remote Code Execution, or Property Injection.

Affected versions: ["0.0.1", "0.0.2", "0.0.3", "0.0.4", "0.0.5", "1.0.0", "1.0.1", "1.0.2", "0.0.6", "1.0.3", "1.0.4", "1.0.5", "1.0.6", "1.0.7", "1.0.8", "1.0.10", "1.0.11", "1.0.12", "1.0.13", "1.0.14", "1.0.15", "1.0.16", "1.1.0", "1.1.1", "1.1.2", "1.1.3", "1.1.4", "1.1.5", "1.1.6", "1.1.7", "1.1.8", "1.1.9", "1.1.10", "1.1.11", "1.1.12", "1.1.13", "1.1.14", "1.1.15", "1.1.16", "1.1.17", "1.1.18", "1.1.19", "1.1.20", "1.1.21", "1.1.22", "1.1.23", "1.1.24", "1.1.25", "1.2.0", "1.3.0", "1.3.1", "1.3.2", "1.3.3", "1.3.4", "1.3.5", "1.3.6", "1.3.7", "1.4.0", "1.5.0", "1.6.0", "1.7.2", "1.7.3", "1.7.4", "1.8.0", "1.8.1", "1.8.2", "1.8.3", "1.8.4", "2.0.0", "2.0.1", "2.0.2", "2.0.3", "2.0.4", "2.1.0", "2.1.1", "2.1.2", "2.1.3", "2.1.4", "2.2.0", "2.2.1", "2.2.2", "2.2.3", "2.2.4", "2.3.0", "2.3.1", "2.3.2", "2.3.3", "2.3.4", "2.3.5", "2.3.6", "2.3.7", "2.3.8", "2.3.9", "2.3.10", "2.3.11", "2.3.12", "2.3.13", "2.4.0", "2.4.1", "2.4.2", "2.4.3", "2.4.4", "2.4.5", "2.4.6", "2.4.7", "2.4.8", "2.4.9", "2.4.10", "2.5.0", "2.5.1", "2.5.2", "2.5.3", "2.5.4", "2.5.5", "2.5.6", "2.5.7", "2.5.8", "2.5.9", "2.5.10", "2.5.11", "2.5.12", "2.5.13", "2.5.14", "2.6.0", "2.6.1", "2.6.2", "2.6.3", "2.6.4", "2.6.5", "2.6.6", "2.6.7", "2.6.8", "2.7.0", "2.7.1", "2.7.2", "2.7.4", "2.7.3", "3.0.0", "3.0.1", "3.0.2", "2.8.0", "3.0.3", "3.1.0", "2.8.1", "3.1.1", "2.8.2", "2.8.3", "2.9.0", "3.2.0", "2.9.1", "3.2.1", "2.9.2", "3.2.2", "3.3.0", "3.3.1", "2.9.3", "3.4.0", "2.9.4", "2.9.5", "3.5.0", "3.5.1", "3.5.2", "3.5.3", "2.9.6", "2.9.7", "3.5.4", "3.5.5", "2.9.8", "2.9.9", "3.5.6", "3.5.7", "3.5.8", "2.9.10", "3.5.9", "3.6.2", "3.5.10", "3.6.3", "3.5.11", "3.6.4", "3.6.5", "3.6.6", "3.6.7", "3.5.12", "3.6.8", "3.6.9", "3.6.10", "3.5.13", "3.5.14", "3.6.11", "3.6.12", "3.6.13", "3.6.14", "3.6.15", "3.5.15", "3.7.0", "3.6.16", "3.5.16", "3.6.17", "3.7.2", "3.0.0-alpha1", "3.0.0-alpha2", "3.0.0-rc0", "3.6.0-rc0", "3.6.0-rc1", "3.6.18", "3.7.3", "3.6.19", "3.6.20", "3.7.4", "3.8.0", "3.8.1", "3.8.2", "3.8.3", "3.8.4", "3.8.5", "3.8.6", "3.8.7", "3.8.8", "3.8.9", "3.8.10", "3.8.11", "3.9.0", "3.8.12", "3.8.13", "3.8.14", "3.8.15", "3.9.1", "3.8.16", "3.9.2", "3.8.17", "3.9.3", "3.8.18", "3.9.4", "3.8.19", "3.9.5", "3.8.20", "3.9.6", "3.8.21", "3.9.7", "3.8.22", "4.0.0-rc0", "4.0.0-rc1", "3.8.23", "4.0.0-rc2", "3.8.24", "4.0.0-rc3", "3.8.25", "4.0.0-rc4", "4.0.0", "4.0.1", "3.8.26", "3.8.27", "4.0.2", "3.8.28", "4.0.3", "3.8.29", "4.0.4", "3.8.30", "4.0.5", "3.8.31", "4.0.6", "3.8.33", "4.0.7", "3.8.34", "4.0.8", "4.1.0", "4.1.1", "4.1.2", "3.8.35", "4.1.3", "4.1.5", "4.1.6", "4.1.7", "4.1.8", "4.1.9", "4.1.10", "4.1.11", "3.8.36", "4.1.12", "4.2.0", "4.2.1", "4.2.2", "4.2.3", "4.2.4", "4.2.5", "3.8.37", "4.2.6", "4.2.7", "4.2.8", "4.2.9", "4.2.10", "4.3.0", "4.3.1", "4.3.2", "4.3.3", "4.3.4", "3.8.38", "4.3.5", "4.3.6", "3.8.39", "4.3.7", "4.4.0", "4.4.1", "4.4.2", "4.4.3", "4.4.4", "4.4.5", "4.4.6", "4.4.7", "4.4.8", "4.4.9", "4.4.10", "4.4.11", "4.4.12", "4.4.13", "3.8.40", "4.4.14", "4.4.15", "4.4.16", "4.4.17", "4.4.18", "4.4.19", "4.4.20", "4.5.0", "4.5.1", "4.5.2", "4.5.3", "4.5.4", "4.5.5", "4.5.6", "4.5.7", "4.5.8", "4.5.9", "4.5.10", "4.6.0", "4.6.1", "4.6.2", "4.6.3", "4.6.4", "4.6.5", "4.6.6", "4.6.7", "4.6.8", "4.7.0", "4.7.1", "4.7.2", "4.7.3", "4.7.4", "4.7.5-pre", "4.7.5", "4.7.6", "4.7.7", "4.7.8", "4.7.9", "4.8.0", "4.8.1", "4.8.2", "4.8.3", "4.8.4", "4.8.5", "4.8.6", "4.8.7", "4.9.0", "4.9.1", "4.9.2", "4.9.3", "4.9.4", "4.9.5", "4.9.6", "4.9.7", "4.9.8", "4.9.9", "4.9.10", "4.10.0", "4.10.1", "4.10.2", "4.10.3", "4.10.4", "4.10.5", "4.10.6", "4.10.7", "4.10.8", "4.11.0", "4.11.1", "4.11.2", "4.11.3", "4.11.4", "4.11.5", "4.11.6", "4.11.7", "4.11.8", "4.11.9", "4.11.10", "4.11.11", "4.11.12", "4.11.13", "4.11.14", "4.12.0", "4.12.1", "4.12.2", "4.12.3", "4.12.4", "4.12.5", "4.12.6", "4.13.0", "4.13.1", "4.13.2", "4.13.3", "4.13.4", "4.13.5", "4.13.6", "4.13.7", "4.13.8", "5.0.0-rc0", "5.0.0-rc1", "5.0.0-rc2", "4.13.9", "5.0.0", "5.0.1", "4.13.10", "5.0.2", "5.0.3", "4.13.11", "5.0.4", "5.0.5", "5.0.6", "5.0.7", "5.0.8", "5.0.9", "5.0.10", "4.13.12", "5.0.11", "5.0.12", "5.0.13", "5.0.14", "5.0.15", "5.0.16", "5.0.17", "5.0.18", "5.1.0", "5.1.1", "4.13.13", "5.1.2", "4.13.14", "5.1.3", "5.1.4", "5.1.5", "5.1.6", "5.1.7", "5.1.8", "5.2.0", "5.2.1", "5.2.2", "5.2.3", "5.2.4", "5.2.5", "5.2.6", "5.2.7", "5.2.8", "4.13.15", "5.2.9", "5.2.10", "4.13.16", "5.2.11", "4.13.17", "5.2.12", "5.2.13", "5.2.14", "5.2.15", "5.2.16", "5.2.17", "5.2.18", "5.3.0", "5.3.1", "5.3.2", "5.3.3", "5.3.4", "5.3.5", "5.3.6", "5.3.7", "5.3.8", "5.3.9", "5.3.10", "5.3.11", "5.3.12", "5.3.13", "5.3.14", "5.3.15", "5.3.16", "5.4.0", "5.4.1", "5.4.2", "5.4.3", "5.4.4", "5.4.5", "4.13.18", "5.4.6", "5.4.7", "5.4.8", "5.4.9", "5.4.10", "5.4.11", "5.4.12", "5.4.13", "5.4.14", "5.4.15", "5.4.16", "5.4.17", "5.4.18", "5.4.19", "5.4.20", "5.4.21", "5.4.22", "5.4.23", "5.5.0", "5.5.1", "5.5.2", "5.5.3", "5.5.4", "5.5.5", "5.5.6", "5.5.7", "5.5.8", "5.5.9", "5.5.10", "5.5.11", "5.5.12", "5.5.13", "5.5.14", "5.5.15", "5.6.0", "5.6.1", "5.6.2", "5.6.3", "5.6.4", "5.6.5", "4.13.19", "5.6.6", "5.6.7", "5.6.8", "5.6.9", "5.6.10", "5.6.11", "5.6.12", "5.6.13", "5.7.0", "5.7.1", "5.7.3", "5.7.4", "5.7.5", "5.7.6", "5.7.7", "5.7.8", "5.7.9", "5.7.10", "5.7.11", "5.7.12", "5.7.13", "5.7.14", "5.8.0", "5.8.1", "5.8.2", "5.8.3", "5.8.4", "5.8.5", "4.13.20", "5.8.6", "5.8.7", "5.8.9", "5.8.10", "5.8.11", "5.8.12", "5.8.13", "5.9.0", "5.9.1", "5.9.2", "5.9.3", "5.9.4", "5.9.5", "5.9.6", "5.9.7", "5.9.9", "5.9.10", "5.9.11", "5.9.12", "5.9.13", "5.9.14", "5.9.15", "5.9.16", "5.9.17", "5.9.18", "5.9.19", "5.9.20", "5.9.21", "5.9.22", "5.9.23", "4.13.21", "5.9.24", "5.9.25", "5.9.26", "5.9.27", "5.9.28", "5.9.29", "5.10.0", "5.10.1", "5.10.2", "5.10.3", "5.10.4", "5.10.5", "5.10.6", "5.10.7", "5.10.8", "5.10.9", "5.10.10", "5.10.11", "5.10.12", "5.10.13", "5.10.14", "5.10.15", "5.10.16", "5.10.17", "5.10.18", "5.10.19", "5.11.0", "5.11.1", "5.11.2", "5.11.3", "5.11.4", "5.11.5", "5.11.6", "5.11.7", "5.11.8", "5.11.9", "5.11.10", "5.11.11", "5.11.12", "5.11.13", "5.11.14", "5.11.15", "5.11.16", "5.11.17", "5.11.18", "5.11.19", "5.11.20", "5.12.0", "5.12.1", "5.12.2", "5.12.3", "5.12.4", "5.12.5", "5.12.6", "5.12.7", "5.12.8", "5.12.9", "5.12.10", "5.12.11", "5.12.12", "5.12.13", "5.12.14", "5.12.15", "5.13.0", "5.13.1", "5.13.2", "5.13.3", "5.13.4", "5.13.5", "5.13.6", "5.13.7", "5.13.8", "5.13.9", "5.13.10", "5.13.11", "5.13.12", "5.13.13", "5.13.14", "6.0.0", "6.0.1", "6.0.2", "6.0.3", "6.0.4", "6.0.5", "6.0.6", "6.0.7", "6.0.8", "6.0.9", "6.0.10", "6.0.11", "6.0.12", "6.0.13", "6.0.14", "6.0.15", "6.1.0", "6.1.1", "6.1.2", "6.1.3", "6.1.4", "6.1.5", "6.1.6", "6.1.7", "6.1.8", "6.1.9", "6.1.10", "6.2.0", "6.2.1", "6.2.2", "6.2.3", "6.2.4", "6.2.5", "6.2.6", "6.2.7", "6.2.8", "6.2.9", "6.2.10", "6.2.11", "6.3.0", "6.3.1", "6.3.2", "6.3.3", "6.3.4", "6.3.5", "6.3.6", "6.3.7", "6.3.8", "6.3.9", "6.4.0", "6.4.1", "6.4.2", "6.4.3", "6.4.4", "6.4.5"]
Secure versions: [6.0.0-rc0, 6.0.0-rc1, 6.0.0-rc2, 7.0.0-rc0, 7.3.3, 6.11.3, 5.13.20, 7.3.4, 6.11.4, 7.4.0, 7.4.1, 6.11.5, 7.4.2, 7.4.3, 6.11.6, 7.4.4, 6.12.0, 7.4.5, 7.5.0, 7.5.1, 7.5.2, 7.5.3, 7.5.4, 7.6.0, 7.6.1, 6.12.1, 7.6.2, 7.6.3, 5.13.21, 8.0.0-rc0, 6.12.2, 7.6.4, 8.0.0, 6.12.3, 7.6.5, 8.0.1, 7.6.6, 8.0.2, 7.6.7, 8.0.3, 6.12.4, 5.13.22, 6.12.5, 7.6.8, 8.0.4, 8.1.0, 6.12.6, 8.1.1, 8.1.2, 8.1.3, 8.2.0, 7.6.9, 6.12.7, 8.2.1, 7.6.10, 8.2.2, 8.2.3, 8.2.4, 8.3.0, 8.3.1, 6.12.8, 7.6.11, 8.3.2, 8.3.3, 8.3.4, 8.3.5, 8.4.0, 7.6.12, 6.12.9, 8.4.1, 7.6.13, 6.13.0, 8.4.2, 8.4.3, 7.7.0, 8.4.4, 8.4.5, 8.5.0, 8.5.1, 7.8.0, 8.5.2, 8.5.3, 7.8.1, 8.5.4, 8.5.5, 8.6.0, 8.6.1, 6.13.1, 8.6.2, 6.13.2, 8.6.3, 6.13.3, 7.8.2, 8.6.4, 8.7.0, 8.7.1, 8.7.2, 8.7.3]
Recommendation: Update to version 8.7.3.

Remote Memory Exposure in mongoose

Published date: 2020-09-01T19:39:37Z
Links:

Versions of mongoose before 4.3.6, 3.8.39 are vulnerable to remote memory exposure.

Trying to save a number to a field of type Buffer on the affected mongoose versions allocates a chunk of uninitialized memory and stores it in the database.

Recommendation

Update to version 4.3.6, 3.8.39 or later.

Affected versions: ["4.0.0", "4.0.1", "4.0.2", "4.0.3", "4.0.4", "4.0.5", "4.0.6", "4.0.7", "4.0.8", "4.1.0", "4.1.1", "4.1.2", "4.1.3", "4.1.5", "4.1.6", "4.1.7", "4.1.8", "4.1.9", "4.1.10", "4.1.11", "4.1.12", "4.2.0", "4.2.1", "4.2.2", "4.2.3", "4.2.4", "4.2.5", "4.2.6", "4.2.7", "4.2.8", "4.2.9", "4.2.10", "4.3.0", "4.3.1", "4.3.2", "4.3.3", "4.3.4", "4.3.5", "3.5.5", "3.5.6", "3.5.7", "3.5.8", "3.5.9", "3.6.2", "3.5.10", "3.6.3", "3.5.11", "3.6.4", "3.6.5", "3.6.6", "3.6.7", "3.5.12", "3.6.8", "3.6.9", "3.6.10", "3.5.13", "3.5.14", "3.6.11", "3.6.12", "3.6.13", "3.6.14", "3.6.15", "3.5.15", "3.7.0", "3.6.16", "3.5.16", "3.6.17", "3.7.2", "3.6.0-rc0", "3.6.0-rc1", "3.6.18", "3.7.3", "3.6.19", "3.6.20", "3.7.4", "3.8.0", "3.8.1", "3.8.2", "3.8.3", "3.8.4", "3.8.5", "3.8.6", "3.8.7", "3.8.8", "3.8.9", "3.8.10", "3.8.11", "3.8.12", "3.8.13", "3.8.14", "3.8.15", "3.8.16", "3.8.17", "3.8.18", "3.8.19", "3.8.20", "3.8.21", "3.8.22", "3.8.23", "3.8.24", "3.8.25", "3.8.26", "3.8.27", "3.8.28", "3.8.29", "3.8.30", "3.8.31", "3.8.33", "3.8.34", "3.8.35", "3.8.36", "3.8.37", "3.8.38"]
Secure versions: [6.0.0-rc0, 6.0.0-rc1, 6.0.0-rc2, 7.0.0-rc0, 7.3.3, 6.11.3, 5.13.20, 7.3.4, 6.11.4, 7.4.0, 7.4.1, 6.11.5, 7.4.2, 7.4.3, 6.11.6, 7.4.4, 6.12.0, 7.4.5, 7.5.0, 7.5.1, 7.5.2, 7.5.3, 7.5.4, 7.6.0, 7.6.1, 6.12.1, 7.6.2, 7.6.3, 5.13.21, 8.0.0-rc0, 6.12.2, 7.6.4, 8.0.0, 6.12.3, 7.6.5, 8.0.1, 7.6.6, 8.0.2, 7.6.7, 8.0.3, 6.12.4, 5.13.22, 6.12.5, 7.6.8, 8.0.4, 8.1.0, 6.12.6, 8.1.1, 8.1.2, 8.1.3, 8.2.0, 7.6.9, 6.12.7, 8.2.1, 7.6.10, 8.2.2, 8.2.3, 8.2.4, 8.3.0, 8.3.1, 6.12.8, 7.6.11, 8.3.2, 8.3.3, 8.3.4, 8.3.5, 8.4.0, 7.6.12, 6.12.9, 8.4.1, 7.6.13, 6.13.0, 8.4.2, 8.4.3, 7.7.0, 8.4.4, 8.4.5, 8.5.0, 8.5.1, 7.8.0, 8.5.2, 8.5.3, 7.8.1, 8.5.4, 8.5.5, 8.6.0, 8.6.1, 6.13.1, 8.6.2, 6.13.2, 8.6.3, 6.13.3, 7.8.2, 8.6.4, 8.7.0, 8.7.1, 8.7.2, 8.7.3]
Recommendation: Update to version 8.7.3.

890 Other Versions

Version License Security Released
6.0.3 MIT 3 2021-08-30 - 21:31 about 3 years
6.0.2 MIT 3 2021-08-26 - 23:34 about 3 years
6.0.1 MIT 3 2021-08-25 - 22:54 about 3 years
6.0.0 MIT 3 2021-08-24 - 22:12 about 3 years
6.0.0-rc2 MIT 2021-08-23 - 19:46 about 3 years
6.0.0-rc1 MIT 2021-08-12 - 20:43 about 3 years
6.0.0-rc0 MIT 2021-08-03 - 20:08 about 3 years
5.13.22 MIT 2024-01-02 - 21:14 10 months
5.13.21 MIT 2023-10-19 - 19:47 about 1 year
5.13.20 MIT 2023-07-12 - 18:27 over 1 year
5.13.19 MIT 1 2023-06-22 - 13:54 over 1 year
5.13.18 MIT 1 2023-06-22 - 13:52 over 1 year
5.13.17 MIT 1 2023-04-04 - 19:25 over 1 year
5.13.16 MIT 1 2023-02-20 - 17:17 over 1 year
5.13.15 MIT 1 2022-08-22 - 17:28 about 2 years
5.13.14 MIT 3 2021-12-27 - 17:58 almost 3 years
5.13.13 MIT 3 2021-11-02 - 19:11 almost 3 years
5.13.12 MIT 3 2021-10-19 - 17:55 about 3 years
5.13.11 MIT 3 2021-10-12 - 21:11 about 3 years
5.13.10 MIT 3 2021-10-05 - 18:34 about 3 years
5.13.9 MIT 3 2021-09-06 - 16:52 about 3 years
5.13.8 MIT 3 2021-08-23 - 15:49 about 3 years
5.13.7 MIT 3 2021-08-11 - 19:17 about 3 years
5.13.6 MIT 3 2021-08-09 - 19:29 about 3 years
5.13.5 MIT 3 2021-07-30 - 15:50 over 3 years
5.13.4 MIT 3 2021-07-28 - 21:12 over 3 years
5.13.3 MIT 3 2021-07-16 - 17:54 over 3 years
5.13.2 MIT 3 2021-07-03 - 21:53 over 3 years
5.13.1 MIT 3 2021-07-02 - 17:55 over 3 years
5.13.0 MIT 3 2021-06-28 - 15:00 over 3 years
5.12.15 MIT 3 2021-06-25 - 18:57 over 3 years
5.12.14 MIT 3 2021-06-15 - 18:22 over 3 years
5.12.13 MIT 3 2021-06-04 - 18:58 over 3 years
5.12.12 MIT 3 2021-05-28 - 14:36 over 3 years
5.12.11 MIT 3 2021-05-24 - 17:01 over 3 years
5.12.10 MIT 3 2021-05-18 - 17:16 over 3 years
5.12.9 MIT 3 2021-05-13 - 18:21 over 3 years
5.12.8 MIT 3 2021-05-10 - 18:12 over 3 years
5.12.7 MIT 3 2021-04-29 - 16:51 over 3 years
5.12.6 MIT 3 2021-04-27 - 21:17 over 3 years
5.12.5 MIT 3 2021-04-19 - 15:12 over 3 years
5.12.4 MIT 3 2021-04-15 - 17:56 over 3 years
5.12.3 MIT 3 2021-03-31 - 18:26 over 3 years
5.12.2 MIT 3 2021-03-22 - 20:58 over 3 years
5.12.1 MIT 3 2021-03-18 - 18:22 over 3 years
5.12.0 MIT 3 2021-03-11 - 19:12 over 3 years
5.11.20 MIT 3 2021-03-11 - 14:41 over 3 years
5.11.19 MIT 3 2021-03-05 - 17:49 over 3 years
5.11.18 MIT 3 2021-02-23 - 20:35 over 3 years
5.11.17 MIT 3 2021-02-17 - 14:36 over 3 years
5.11.16 MIT 3 2021-02-12 - 21:45 over 3 years
5.11.15 MIT 3 2021-02-03 - 19:05 over 3 years
5.11.14 MIT 3 2021-01-28 - 22:38 almost 4 years
5.11.13 MIT 3 2021-01-20 - 16:35 almost 4 years
5.11.12 MIT 3 2021-01-14 - 20:39 almost 4 years
5.11.11 MIT 3 2021-01-08 - 17:53 almost 4 years
5.11.10 MIT 3 2021-01-04 - 19:40 almost 4 years
5.11.9 MIT 3 2020-12-28 - 20:48 almost 4 years
5.11.8 MIT 3 2020-12-14 - 22:29 almost 4 years
5.11.7 MIT 3 2020-12-10 - 23:22 almost 4 years
5.11.6 MIT 3 2020-12-09 - 17:42 almost 4 years
5.11.5 MIT 3 2020-12-07 - 18:52 almost 4 years
5.11.4 MIT 3 2020-12-04 - 17:14 almost 4 years
5.11.3 MIT 3 2020-12-03 - 19:25 almost 4 years
5.11.2 MIT 3 2020-12-02 - 22:33 almost 4 years
5.11.1 MIT 3 2020-12-01 - 20:08 almost 4 years
5.11.0 MIT 3 2020-11-30 - 21:52 almost 4 years
5.10.19 MIT 3 2020-11-30 - 17:38 almost 4 years
5.10.18 MIT 3 2020-11-29 - 13:19 almost 4 years
5.10.17 MIT 3 2020-11-27 - 20:35 almost 4 years
5.10.16 MIT 3 2020-11-25 - 16:09 almost 4 years
5.10.15 MIT 3 2020-11-16 - 21:42 almost 4 years
5.10.14 MIT 3 2020-11-12 - 21:38 almost 4 years
5.10.13 MIT 3 2020-11-06 - 15:47 almost 4 years
5.10.12 MIT 3 2020-11-04 - 20:09 almost 4 years
5.10.11 MIT 3 2020-10-26 - 22:15 about 4 years
5.10.10 MIT 3 2020-10-23 - 16:52 about 4 years
5.10.9 MIT 3 2020-10-09 - 15:40 about 4 years
5.10.8 MIT 3 2020-10-05 - 21:39 about 4 years
5.10.7 MIT 3 2020-09-24 - 21:26 about 4 years
5.10.6 MIT 3 2020-09-18 - 19:10 about 4 years
5.10.5 MIT 3 2020-09-11 - 17:29 about 4 years
5.10.4 MIT 3 2020-09-09 - 14:43 about 4 years
5.10.3 MIT 3 2020-09-03 - 20:08 about 4 years
5.10.2 MIT 3 2020-08-28 - 15:10 about 4 years
5.10.1 MIT 3 2020-08-26 - 19:27 about 4 years
5.10.0 MIT 3 2020-08-14 - 16:41 about 4 years
5.9.29 MIT 3 2020-08-13 - 19:07 about 4 years
5.9.28 MIT 3 2020-08-07 - 20:35 about 4 years
5.9.27 MIT 3 2020-07-31 - 15:45 over 4 years
5.9.26 MIT 3 2020-07-27 - 21:33 over 4 years
5.9.25 MIT 3 2020-07-17 - 18:50 over 4 years
5.9.24 MIT 3 2020-07-13 - 19:13 over 4 years
5.9.23 MIT 3 2020-07-10 - 17:43 over 4 years
5.9.22 MIT 3 2020-07-06 - 21:49 over 4 years
5.9.21 MIT 3 2020-07-01 - 22:02 over 4 years
5.9.20 MIT 3 2020-06-22 - 21:24 over 4 years
5.9.19 MIT 3 2020-06-15 - 15:25 over 4 years
5.9.18 MIT 3 2020-06-05 - 19:45 over 4 years
5.9.17 MIT 3 2020-06-02 - 20:26 over 4 years