GHSA-h8hf-x3f4-xwgp
Mongoose Vulnerable to Prototype Pollution in Schema Object
Quick fix
GHSA-h8hf-x3f4-xwgp — mongoose: upgrade to the fixed version with the command below.
npm install mongoose@6.4.6Details
### Description Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment.
Affected versions of this package are vulnerable to Prototype Pollution. The `Schema.path()` function is vulnerable to prototype pollution when setting the `schema` object. This vulnerability allows modification of the Object prototype and could be manipulated into a Denial of Service (DoS) attack.
### Proof of Concept ```js // poc.js const mongoose = require('mongoose'); const schema = new mongoose.Schema();
malicious_payload = '__proto__.toString'
schema.path(malicious_payload, [String])
x = {} console.log(x.toString()) // crashed (Denial of service (DoS) attack) ```
### Impact This vulnerability can be manipulated to exploit other types of attacks, such as Denial of service (DoS), Remote Code Execution, or Property Injection.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-24304[ADVISORY]
- https://github.com/Automattic/mongoose/issues/12085[WEB]
- https://github.com/Automattic/mongoose/commit/6a197316564742c0422309e1b5fecfa4faec126e[WEB]
- https://github.com/Automattic/mongoose/commit/a45cfb6b0ce0067ae9794cfa80f7917e1fb3c6f8[WEB]
- https://github.com/Automattic/mongoose/blob/51e758541763b6f14569744ced15cc23ab8b50c6/lib/schema.js#L88-L141[WEB]
- https://huntr.dev/bounties/055be524-9296-4b2f-b68d-6d5b810d1ddd[WEB]