VDB
Sign up
MEDIUM5.1

GHSA-r5xw-q988-826m

Remote Memory Exposure in mongoose

Quick fix

GHSA-r5xw-q988-826m — mongoose: upgrade to the fixed version with the command below.

npm install mongoose@3.8.39

Details

Versions of `mongoose` before 4.3.6, 3.8.39 are vulnerable to remote memory exposure.

Trying to save a number to a field of type Buffer on the affected mongoose versions allocates a chunk of uninitialized memory and stores it in the database.

## Recommendation

Update to version 4.3.6, 3.8.39 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/mongoose
Introduced in: 3.5.5Fixed in: 3.8.39
Fixnpm install mongoose@3.8.39
npm/mongoose
Introduced in: 4.0.0Fixed in: 4.3.6
Fixnpm install mongoose@4.3.6

References