VDB
Sign up
CRITICAL9.1

GHSA-8687-vv9j-hgph

Improper Input Validation in Automattic Mongoose

Quick fix

GHSA-8687-vv9j-hgph — mongoose: upgrade to the fixed version with the command below.

npm install mongoose@5.7.5

Details

Automattic Mongoose through 5.7.4 allows attackers to bypass access control (in some applications) because any query object with a `_bsontype` attribute is ignored. For example, adding `"_bsontype":"a"` can sometimes interfere with a query filter. NOTE: this CVE is about Mongoose's failure to work around this _bsontype special case that exists in older versions of the bson parser (aka the mongodb/js-bson project).

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/mongoose
Introduced in: 5.0.0Fixed in: 5.7.5
Fixnpm install mongoose@5.7.5
npm/mongoose
Introduced in: 0Fixed in: 4.13.21
Fixnpm install mongoose@4.13.21

References