VDB
Sign up
HIGH

GHSA-hxwc-5vw9-2w4w

NoSQL Injection in loopback-connector-mongodb

Quick fix

GHSA-hxwc-5vw9-2w4w — loopback-connector-mongodb: upgrade to the fixed version with the command below.

npm install loopback-connector-mongodb@3.6.0

Details

Versions of `loopback-connector-mongodb` prior to 3.6.0 are vulnerable to NoSQL Injection. Filters passed to the database query are not properly sanitized which leads to execution of code on the database driver and data leak.

## Recommendation

Upgrade to version 3.6.0 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/loopback-connector-mongodb
Introduced in: 0Fixed in: 3.6.0
Fixnpm install loopback-connector-mongodb@3.6.0

References